‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

7 days ago
1 min read
Updated: 3 days ago
Dubbed SalesBleed, the flaws could be exploited via Web-to-Lead forms, Salesforce’s official lead-collection mechanism, which also provides a direct path to the CRM.
Malicious instructions injected into a Web-to-Lead lead would remain dormant until an employee asks an Agentforce agent to interact with the submission, causing the agent to process the poisoned lead and execute the hidden instructions.
Comments