<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p" -->

---
title: Salesforce Agentforce vulns allowed 0-click CRM data...
description: Zenity Labs discovered three vulnerabilities in Salesforce Agentforce, collectively dubbed SalesBleed, that let attackers plant indirect prompt injections via...
canonical: https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing | daily.dev
og:description: Zenity Labs discovered three vulnerabilities in Salesforce Agentforce, collectively dubbed SalesBleed, that let attackers plant indirect prompt injections via...
og:url: https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p
og:image: https://api.daily.dev/og/posts/LnxC3zF0P.png
og:image:alt: Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

**[The Register](https://daily.dev/sources/theregister)** · 5 min read · 1 upvotes · 0 comments

## Summary

Zenity Labs discovered three vulnerabilities in Salesforce Agentforce, collectively dubbed SalesBleed, that let attackers plant indirect prompt injections via public Web-to-Lead forms to hijack AI agents. Two flaws enabled zero-click exfiltration of CRM data by bypassing Trusted URLs redaction and embedding stolen data in image tags or Slack link-unfurling requests. A third flaw let attackers or malicious insiders send phishing messages under the agent's own identity via a Slack reply action that lacked confirmation and attribution. Zenity reported the issues to Salesforce on June 1, and by September 21 confirmed all three had been fixed.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958>

## Questions this post answers

### What were the SalesBleed vulnerabilities in Salesforce Agentforce?

SalesBleed refers to three vulnerabilities in Salesforce Agentforce discovered by Zenity Labs: two enabled zero-click exfiltration of CRM data by planting indirect prompt injections in public Web-to-Lead forms and bypassing Trusted URLs redaction, and a third allowed anonymous phishing through a Slack reply action lacking user confirmation and attribution. All three were reported June 1 and confirmed fixed by September 21.

_Teams securing AI agents against prompt injection can track disclosures like SalesBleed on daily.dev._

### How did attackers bypass Salesforce's Trusted URLs redaction to steal CRM data?

Attackers exploited weaknesses where Salesforce's Trusted URLs mechanism failed to register hostnames ending in unrecognized top-level domains and mishandled certain characters during URL parsing. This let a poisoned Web-to-Lead submission inject instructions that made the Agentforce agent query CRM records, embed the data as a subdomain in an image tag URL, and silently send it via DNS or HTTPS requests to an attacker-controlled server, with no click required.

_Developers hardening agent-to-CRM integrations can follow writeups like this on daily.dev._

### How could an attacker send phishing messages using Salesforce Agentforce's Slack integration?

The Reply to a Slack Thread Agentforce action did not require user confirmation before sending a message and lacked visible attribution to the invoking user. A malicious insider chatting with the agent, or an external attacker via an indirect prompt injection in a Web-to-Lead form, could exploit this to send phishing messages under the trusted agent's own identity while remaining anonymous.

_Anyone evaluating AI agent permissions in Slack integrations can follow similar security findings on daily.dev._

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#phishing](https://daily.dev/tags/phishing), [#salesforce](https://daily.dev/tags/salesforce), [#prompt-injection](https://daily.dev/tags/prompt-injection), [#data-exfiltration](https://daily.dev/tags/data-exfiltration)

[View this post on daily.dev](https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","url":"https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p"},"datePublished":"2026-09-24T19:02:45.488Z","dateModified":"2026-09-24T19:03:07.721Z","description":"Zenity Labs discovered three vulnerabilities in Salesforce Agentforce, collectively dubbed SalesBleed, that let attackers plant indirect prompt injections via...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bc9a6678421f41f88c4c922c43feb6a5?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/bc9a6678421f41f88c4c922c43feb6a5?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,phishing,salesforce,prompt-injection,data-exfiltration","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing-lnxc3zf0p#faq","mainEntity":[{"@type":"Question","name":"What were the SalesBleed vulnerabilities in Salesforce Agentforce?","acceptedAnswer":{"@type":"Answer","text":"SalesBleed refers to three vulnerabilities in Salesforce Agentforce discovered by Zenity Labs: two enabled zero-click exfiltration of CRM data by planting indirect prompt injections in public Web-to-Lead forms and bypassing Trusted URLs redaction, and a third allowed anonymous phishing through a Slack reply action lacking user confirmation and attribution. All three were reported June 1 and confirmed fixed by September 21. Teams securing AI agents against prompt injection can track disclosures like SalesBleed on daily.dev."}},{"@type":"Question","name":"How did attackers bypass Salesforce's Trusted URLs redaction to steal CRM data?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited weaknesses where Salesforce's Trusted URLs mechanism failed to register hostnames ending in unrecognized top-level domains and mishandled certain characters during URL parsing. This let a poisoned Web-to-Lead submission inject instructions that made the Agentforce agent query CRM records, embed the data as a subdomain in an image tag URL, and silently send it via DNS or HTTPS requests to an attacker-controlled server, with no click required. Developers hardening agent-to-CRM integrations can follow writeups like this on daily.dev."}},{"@type":"Question","name":"How could an attacker send phishing messages using Salesforce Agentforce's Slack integration?","acceptedAnswer":{"@type":"Answer","text":"The Reply to a Slack Thread Agentforce action did not require user confirmation before sending a message and lacked visible attribution to the invoking user. A malicious insider chatting with the agent, or an external attacker via an indirect prompt injection in a Web-to-Lead form, could exploit this to send phishing messages under the trusted agent's own identity while remaining anonymous. Anyone evaluating AI agent permissions in Slack integrations can follow similar security findings on daily.dev."}}]}
```

