SalesBleed: Three Zero-Click Flaws Found in Salesforce Agentforce
Zenity Labs disclosed three zero-click vulnerabilities in Salesforce Agentforce that let attackers use prompt injection in a web form to make the AI agent exfiltrate CRM data via DNS queries. All flaws are patched, but the pattern applies to any enterprise agent.
- Attack abused public Salesforce Web-to-Lead forms to inject a prompt payload
- Data left via DNS subdomains, bypassing HTTP filtering and DLP systems
- Trusted URLs bypass: .fun TLD was missing and brackets broke URL parsing
- In Slack, automatic link unfurling triggered exfiltration with no click
Read next
Security