Zenity Labs has uncovered three significant vulnerabilities in Salesforce Agentforce that posed serious security threats by enabling zero-click data exfiltration and phishing attacks. These vulnerabilities, collectively named SalesBleed, were particularly concerning because they allowed attackers to exploit Salesforce's Web-to-Lead forms, the primary method for gathering leads. By injecting malicious code into these forms, attackers could remain undetected until an Agentforce agent processed the poisoned data, which then activated the harmful instructions.

Two of the identified vulnerabilities were linked to the Trusted URLs security mechanism, which is supposed to prevent Agentforce from displaying content from untrusted sources. However, Zenity Labs found that this mechanism failed to recognize top-level domains and could be tricked by certain character sequences, allowing for zero-click CRM data exfiltration. Attackers could use HTML image tags to silently send this data to servers they controlled.

The third vulnerability was associated with the integration between Agentforce and Slack. This flaw allowed attackers to weaponize the Agentforce agent, automatically sending CRM data to malicious servers when Slack retrieved link previews. Furthermore, attackers could manipulate the agent to distribute phishing messages to internal Slack channels, deceiving employees into believing these messages came from a trusted source. Such phishing attacks could potentially grant attackers access to sensitive applications through compromised credentials.

Zenity Labs reported these vulnerabilities to Salesforce on June 1, and by August 19, Salesforce confirmed that all issues had been resolved, safeguarding users from these threats.