Overview
- Zenity Labs found a chain of three vulnerabilities called SalesBleed that let attackers seed hidden prompt‑injection instructions into public Web‑to‑Lead forms so Agentforce would execute them during routine processing.
- Two flaws abused Trusted URL parsing so the agent could build image or link references that caused DNS queries and other outbound requests carrying CRM fields to attacker domains.
- A third flaw let an attacker weaponize Agentforce’s Slack integration so the agent could post phishing messages that appeared to come from a trusted internal system.
- Zenity reported the issues to Salesforce on June 1, Salesforce implemented fixes for the three bugs on August 18–19, and the research was publicly detailed in late September with no confirmed in‑the‑wild exploitation.
- Researchers warn the risk is a general pattern for any AI agent that ingests untrusted external records, renders rich content back to users, and has access to sensitive backend data, and they recommend patching, strict rendering controls, least‑privilege access, and DNS/outbound egress monitoring.