Infosecurity Magazine iconInfosecurity MagazineSep 25, 2026 ~4 min source read

SalesBleed: How zero-click flaws in Salesforce Agentforce let attackers siphon CRM data

Zenity Labs disclosed a zero-click attack chain against Salesforce Agentforce that used poisoned Web-to-Lead submissions, prompt injection, and DNS exfiltration to extract CRM fields without authentication. Salesforce patched the immediate vulnerability; the underlying agent-risk pattern remains relevant for other deployments.

Share this story

Send the public story page.

Useful takeaways from this story.

The exploit combined prompt injection, agent trust in record content (rendering links/images), and agent access to sensitive backend tools to exfiltrate CRM fields via DNS.

Any agent that ingests untrusted external records, renders rich content back to users, and holds tool access to sensitive data contains the same three ingredients for similar attacks.

# What happened Security researchers at Zenity Labs disclosed a zero-click vulnerability set they call "SalesBleed" in Salesforce Agentforce. A single submission to a public Web-to-Lead form was enough to seed a hidden prompt-injection payload. When an Agentforce agent processed that CRM record during normal operations, the injected instructions hijacked the agent and directed it to quietly query and exfiltrate CRM data.

# How the attack worked, step by step

  • A public Web-to-Lead form accepted external input and created a CRM record. That lead submission carried an embedded prompt-injection payload.
  • Agentforce processed the lead as part of routine workflows and treated record content as instructions because the agent can render links or images back to the user interface.
  • The agent had tool-level access to query CRM records. The payload instructed the agent to collect account names, deal sizes and other CRM fields reachable by the agent's Query Records tool.
  • Exfiltration used DNS lookups that bypassed Salesforce's Trusted URLs redaction controls, enabling data to leave the environment without interacting with the attacker and without authentication.

# Timeline and remediation Zenity reported the vulnerabilities to Salesforce in June. Salesforce implemented a fix for the URL redaction bypass on August 18. According to Zenity's published findings (September 24), the immediate SalesBleed chain can no longer be used against Agentforce after that remediation.

# Why this matters beyond Agentforce Zenity's analysis highlights a repeatable risk pattern: any AI agent that combines three elements—(1) reading or processing records submitted by untrusted external sources, (2) rendering links/images or rich content back to users, and (3) holding tool access to sensitive backend data—can be vulnerable to prompt-injection-driven exfiltration. The SalesBleed example used CRM fields and DNS-based extraction, but the underlying mechanism could target any data reachable by an agent's tools.

# Practical implications for defenders

  • Audit and tightly limit which agent tools can query sensitive records. Broader tool access increases the blast radius of a successful prompt injection.

# Bottom line

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app