SECURITY researchers at Zenity Labs disclosed three Salesforce Agentforce vulnerabilities, dubbed “SalesBleed”, that could have enabled attackers to exfiltrate sensitive CRM data without a user clicking anything, or use an Agentforce agent to send phishing messages. The attacks began with malicious instructions hidden in a Salesforce Web-to-Lead submission. The instructions remained dormant until an employee asked Agentforce to process the lead, at which point the trusted agent could execute them.
Two flaws involved weaknesses in Agentforce’s Trusted URLs controls, which are intended to prevent agents from loading or sending content to unapproved domains. Zenity said the controls failed to recognise top-level domains and could be bypassed using character sequences that altered URL parsing. A poisoned lead could therefore access leads and accounts data and transmit it to an attacker-controlled server through HTML image tags.
The report said Agentforce could claim the content had been blocked even though the data had already been sent. A related attack used specially constructed links and the Agentforce-Slack integration, prompting Slack to request previews containing CRM data.
The third flaw affected the Slack integration and allowed an attacker to make the agent post phishing messages to internal channels under its trusted identity, because the agent did not identify the person who initiated the message. Zenity reported the vulnerabilities to Salesforce on 1 June, and Salesforce confirmed that all three had been fixed by 19 August.