Vulnerability in Salesforce AI could be tricked into leaking CRM data
- Joseph K

- Sep 24, 2025
- 1 min read
A newly disclosed critical vulnerability in Salesforce’s Agentforce platform could trick the AI agent into leaking sensitive CRM data through indirect prompt injection.
Researchers at Noma Security, who identified the bug dubbed “ForcedLeak,” said in a blog post shared with CSO ahead of its publication on Thursday that it could be exploited by attackers inserting malicious instructions into a routine customer form.
Comments