Salesforce AI flaws enabled click-free CRM theft and agent impersonation
Three Salesforce Agentforce vulnerabilities, dubbed “SalesBleed”, enabled attackers to poison public lead forms, hijack AI agents and steal CRM data without an employee clicking anything. The flaws also allowed phishing messages to be sent under an agent’s identity, highlighting the difficulty of containing increasingly capable AI systems and enforcing their security guardrails.
The attacks used indirect prompt injection in Web-to-Lead submissions, triggered when an employee asked Agentforce about leads. Weaknesses in Trusted URLs and URL parsing let stolen account details be embedded in image requests to attacker-controlled servers, including through Slack’s automatic link unfurling; Salesforce and Zenity Labs have since fixed the attack chains.
- Poisoned leads could trigger silent, zero-click Salesforce data theft.
- Attackers could impersonate Agentforce agents to send phishing messages.
- The flaws were fixed, but AI-agent containment remains challenging.
Americas Cybersecurity Technology World
Read the full article at the source →
Originally published by The Register as “Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing”.