Zenity finds zero-click flaws in Salesforce Agentforce
Zenity Labs disclosed SalesBleed, a zero-click attack chain in Salesforce Agentforce where hidden prompt injections in Web-to-Lead forms made an AI agent exfiltrate CRM data via DNS without any victim interaction or authentication. Salesforce fixed the URL redaction bypass on August 18.
- SalesBleed needed no clicks or stolen credentials
- Payloads were planted via public Web-to-Lead forms
- CRM data was exfiltrated via DNS, bypassing Trusted URLs
- Salesforce patched the flaw on August 18
Read next
Security