
Salesforce Agentforce Faces SalesBleed Data-Theft and Phishing Flaw Claims
The AMW Read
The alleged flaws materially challenge the security boundary of a major enterprise-agent platform by combining prompt injection, CRM data exposure, and trusted-channel phishing.
Salesforce Agentforce Faces SalesBleed Data-Theft and Phishing Flaw Claims
Zenity Labs disclosed three alleged flaws in Salesforce’s Agentforce platform that it calls SalesBleed. The research describes an attack chain in which an attacker submits hidden instructions through a public Web-to-Lead form, then waits for an employee to ask an Agentforce assistant to review recent leads. According to the report, the agent could be induced to retrieve CRM data and place it in an HTML image URL, causing an outbound request without a user click. Zenity also alleged that gaps in Agentforce’s Trusted URLs filtering allowed certain destinations or malformed URLs to evade redaction.
The disclosure is consequential because it targets the boundary between untrusted external inputs and enterprise agents with access to CRM records and workplace communications. The reported Slack-related flaw could allow a deployed Agentforce bot to post phishing links through its trusted identity, without the normal confirmation step or clear attribution of the triggering action. That complicates Salesforce’s recent positioning of Agentforce around permission-aware CRM actions and multi-agent governance: controls must cover not only what an agent is authorized to access, but also how it interprets retrieved content and where its outputs can travel.
For builders, public forms, tickets, emails, and knowledge bases should be treated as potentially adversarial inputs whenever an agent can query sensitive systems or generate links and messages. Segregating retrieval from action, constraining outbound rendering and network destinations, requiring confirmation for external communications, and testing URL filters against parser edge cases are concrete design requirements. For investors and enterprise buyers, this is a reminder that agent adoption depends on operational security evidence, not only workflow automation claims; hosted-service patching can reduce customer remediation work, but it also leaves customers dependent on the vendor’s speed and disclosure practices.

