The rapid deployment of autonomous AI agents within enterprise CRM environments has introduced a new category of high-stakes security risks, as evidenced by the discovery of the "SalesBleed" vulnerability set. Zenity Labs has identified three distinct flaws in Salesforce Agentforce that could allow attackers to bypass established security boundaries to steal sensitive data or impersonate trusted system identities. These vulnerabilities specifically target the mechanisms intended to contain AI behavior, potentially turning a single untrusted lead into a vector for zero-click data exfiltration and sophisticated internal phishing. By exploiting the way Agentforce processes external information, attackers could theoretically extract customer deal sizes, pricing, and contract details without any employee interaction. This discovery highlights a critical tension in the enterprise AI transition: the gap between theoretical guardrails and the practical reality of software-defined security boundaries.
SalesBleed Exploits Web-to-Lead Entry Points
The primary attack vector identified by Zenity Labs begins with Salesforce’s official Web-to-Lead mechanism, a standard tool used by organizations to collect external lead information directly into the CRM. Researchers demonstrated that attackers can plant malicious instructions within these Web-to-Lead submissions, creating a "poisoned" lead that remains dormant until an employee interacts with it. When an Agentforce agent processes this information—often triggered by a routine employee query—the hidden instructions can hijack the agent's autonomy. This allows the agent to perform unauthorized actions, such as exfiltrating sensitive records, while simultaneously returning what appears to be a standard, legitimate response to the user.
The research specifically targeted "Trusted URLs," a Salesforce security feature designed to prevent Agentforce from communicating with unapproved external domains. Zenity Labs found that weaknesses in how this mechanism parses character sequences and recognizes top-level domains allow attackers to bypass these restrictions. By embedding retrieved CRM data into image requests directed at attacker-controlled servers, the vulnerabilities enable zero-click exfiltration. In these scenarios, the sensitive data is transmitted automatically when the response renders, requiring no click or approval from the employee. This bypass effectively nullifies the intended security boundary between the enterprise environment and untrusted external destinations.
Agentforce-Slack Integration and Identity Risks
Beyond direct data theft, the SalesBleed findings reveal significant risks regarding the Agentforce-Slack integration, specifically concerning identity and social engineering. Zenity Labs discovered that the integration allows an agent to post messages across different Slack channels without reliably identifying the specific user who initiated the action. This flaw creates two distinct paths for exploitation: an insider could use the vulnerability to post phishing messages anonymously under the agent's identity, or an external attacker could use indirect prompt injection via a poisoned lead to force the agent to distribute phishing links throughout Slack threads.
Because these messages originate from a trusted AI agent already operating within the enterprise's internal communication channels, they carry a high degree of perceived legitimacy. Employees receiving these messages are more likely to follow malicious links, which could lead to the compromise of credentials for email, Slack, source code repositories, and other critical enterprise applications. This effectively weaponizes the trusted identity of the enterprise AI agent, transforming a productivity tool into a vehicle for sophisticated, internal social engineering attacks. Salesforce has since worked with Zenity Labs to remediate the reported issues, including the Trusted URLs bypasses and the Slack attribution flaw.
Key Takeaways
- Attackers can use poisoned Web-to-Lead forms to trigger zero-click exfiltration of sensitive CRM data, including pricing and contracts.
- Vulnerabilities in Salesforce's Trusted URLs mechanism allow Agentforce to bypass security boundaries by embedding data in image requests.
- Flaws in the Agentforce-Slack integration enable attackers to impersonate trusted AI agents to distribute phishing messages internally.
TechInsyte's Take
In our view, the SalesBleed discovery serves as a stark warning that "guardrails" are only as effective as the underlying code's ability to parse complex, adversarial inputs. The fact that an attacker can leverage a standard, official mechanism like Web-to-Lead to bypass Trusted URLs suggests that the attack surface for AI agents is significantly wider than traditional SaaS vulnerabilities. This is not merely a configuration error; it is a fundamental challenge in how autonomous agents interpret and act upon untrusted data. For CIOs and CISOs, this signals that deploying AI agents requires moving beyond simple permission-based security toward a model of continuous, layered visibility. Organizations cannot rely solely on "hard boundaries" like Trusted URLs; they must implement deep monitoring of agent behavior, tool invocation, and data access patterns to detect when an agent has been subverted from within.
Questions & Answers
How can an attacker trigger data theft without any user interaction?
Attackers can use "poisoned" instructions within a Web-to-Lead form. When an Agentforce agent processes this data, it can be manipulated to embed sensitive CRM information into image requests. Because these images render automatically in the user interface, the data is transmitted to an attacker-controlled server via a zero-click mechanism.
What specific types of sensitive data are at risk of being exfiltrated?
The research indicates that any data accessible under the user's permissions could be targeted. Specific examples provided include customer deal sizes, prospect records, contact information, pricing, and contracts.
How does the Agentforce-Slack integration pose a phishing risk?
The integration flaw allows messages to be sent to Slack channels without clearly identifying the initiating user. This allows attackers to use the trusted identity of the AI agent to distribute phishing links, making the messages appear to come from a legitimate, internal system.
Has Salesforce addressed these security vulnerabilities?
Yes. Following responsible disclosure on June 1, 2026, Salesforce worked with Zenity Labs to investigate and remediate the issues. The Trusted URLs bypasses were addressed within approximately two weeks, and the Slack attribution issue has also been remediated.
Source: http://www.zenity.io./