Salesforce fixes SalesBleed flaws enabling zero-click data exfiltration
Summary
Three vulnerabilities in Salesforce Agentforce, collectively dubbed "SalesBleed," have been identified by Zenity Labs, potentially allowing attackers to exfiltrate sensitive CRM data and execute phishing attacks without direct interaction. The flaws exploit Salesforce's Web-to-Lead forms, relying on weaknesses within the Trusted URLs security mechanism and the integration with Slack. Zenity Labs found that these vulnerabilities enabled zero-click data exfiltration, where malicious payloads remain dormant until triggered by employee interactions with Agentforce agents. Salesforce confirmed the resolution of these issues by August 19, following their disclosure on June 1.
Tokens
$CRM
Analysis
Salesforce: Salesforce is a provider of cloud-based customer relationship management software and related enterprise tools, including its Agentforce AI agent platform for automating sales and customer service tasks. The company’s Web-to-Lead mechanism serves as an official channel for collecting potential customer information directly into its CRM system. Vulnerabilities in Agentforce allowed these trusted components to be misused for unauthorized data access and messaging. Zenity Labs: Zenity Labs is a cybersecurity research firm focused on identifying risks in AI-driven automation and enterprise platforms. It discovered the SalesBleed vulnerabilities in Salesforce Agentforce and disclosed details of the flaws along with proof-of-concept exploitation methods. The firm’s work highlighted weaknesses in security controls for AI agents interacting with CRM data and external integrations. Attack Surface: Exploitation relied on Salesforce’s official Web-to-Lead forms combined with weaknesses in Trusted URLs and the Agentforce-Slack integration. Vulnerability Type: The flaws enabled zero-click data exfiltration and the weaponization of AI agents for internal phishing without direct attacker interaction. Disclosure and Remediation: Zenity Labs reported the issues to Salesforce, which confirmed resolution of all three vulnerabilities.
Categories
techai_agents