'SalesBleed' Flaws in Salesforce Agentforce Exposed CRM Data with Zero Clicks
Researchers at Zenity Labs discovered three security flaws in Salesforce Agentforce, collectively named SalesBleed, that allowed attackers to hijack the platform's AI agents. The flaws let malicious actors silently extract sensitive CRM data with no click required from the victim, and even send phishing messages that appeared to come from the AI agent itself. Zenity reported the issues to Salesforce, which worked with the firm to fix them; the attack chains no longer function.
The attack worked by planting hidden instructions inside a public Web-to-Lead form. These instructions stayed dormant until an employee asked an Agentforce agent a routine question about leads. This triggered the agent to quietly query sensitive account data, such as company names and deal sizes, and leak it out through a disguised web address controlled by the attacker.
Zenity's co-founder Michael Bargury said the case highlights a broader challenge in securing AI agents: even well-designed guardrails can be bypassed in unexpected ways once agents interact with real-world data. He compared it to a similar incident involving OpenAI and Hugging Face, warning that as AI agents become more capable, businesses need ongoing monitoring rather than one-time security design.
Key Takeaway: Businesses using AI-powered CRM tools should ensure any public-facing forms feeding data into those systems are closely monitored and treated as a potential attack surface, not just a customer contact point.