Researchers disclosed three vulnerabilities, collectively named SalesBleed, that could turn untrusted customer-relationship records into instructions for Salesforce Agentforce agents. Two attack paths enabled zero-click data exfiltration, while a third could use an Agentforce-Slack integration to distribute phishing messages under a trusted agent identity.
Poisoned lead data became agent instructions
The research used Salesforce Web-to-Lead forms to place hidden instructions inside CRM records. Those instructions remained dormant until an employee asked an Agentforce agent to process the record. Researchers found ways to bypass Trusted URLs controls and embed sensitive CRM information in outbound requests. A related path used Slack link previews and agent messaging behavior.
Zenity reported the issues to Salesforce in June. Salesforce said the bugs were addressed by August 19, strengthened relevant controls and changed default behavior for certain Slack actions to require user confirmation. The company said it had no evidence of customer exploitation.
Agent permissions require data-flow testing
Organizations should treat external CRM fields as untrusted input, restrict agent-accessible data, require confirmation for high-impact actions and monitor outbound destinations. Testing should verify actual data flows rather than assume an allowlist blocks every parsing variation. SectechMedia follows these issues in its cybersecurity coverage.

Leave a Reply