Salesforce Agentforce Flaws Turn Leads Into Attackers
Zenity Labs found three "SalesBleed" flaws in Salesforce Agentforce that let poisoned lead submissions bypass agent guardrails, steal CRM data, and send phishing messages under the agent’s identity. Salesforce has patched the issues, and Zenity says it validated the fixes.
The attack starts with a public Web-to-Lead form. A hidden prompt is buried in the submitted lead, then an Agentforce agent later reads that lead as normal business data and follows the hidden instructions, which can make it query records, leak fields, or send messages as if it were a staff user.
The lesson lands anywhere an AI assistant can read user-submitted content and take action: that intake path is not just data, it can become the prompt. If your agents sit on top of public forms, tickets, or inboxes, the exposure is not limited to logged-in users or trusted internal records.