Gbhackers iconGbhackersSep 25, 2026

Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection

Security researchers have revealed a vulnerability chain known as "SalesBleed," associated with Salesforce's Agentforce. This vulnerability could allow attackers to extract sensitive CRM data through an indirect prompt injection embedded in a public Web-to-Lead form.

Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection

Share this story

Send the public story page.

Useful takeaways from this story.

Security researchers have revealed a vulnerability chain known as "SalesBleed," associated with Salesforce's Agentforce.

This vulnerability could allow attackers to extract sensitive CRM data through an indirect prompt injection embedded in a public Web-to-Lead form.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Security researchers have revealed a vulnerability chain known as "SalesBleed," associated with Salesforce's Agentforce. This vulnerability could allow attackers to extract sensitive CRM data through an indirect prompt injection embedded in a public Web-to-Lead form.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app