AIToday
Large Language ModelsAI Safety & AlignmentTop Companies' AI MovesTop Companies AIPublished: Sep 27, 2026, 06:30 JST

Zenity Labs finds zero-click bugs in Salesforce Agentforce

Zenity Labs finds zero-click bugs in Salesforce Agentforce

3 Key Points

  1. What happened

    Zenity Labs published findings on September 24 detailing 'SalesBleed,' an attack chain that slipped hidden prompt injection payloads into public Web-to-Lead forms, hijacking Agentforce agents to quietly exfiltrate CRM data. Salesforce fixed the URL redaction bypass on August 18.

  2. Why it matters

    Any AI agent that ingests untrusted external records, renders links or images back to users, and holds sensitive tool permissions may face the same latent exfiltration path, Zenity researchers warned.

  3. What to watch

    The fixes apply to SalesBleed specifically, so the outcome hinges on whether other vendors' agents share the same three ingredients and how quickly they shore up prompt injection defenses.

WHO IT HITSEnterprise security teams running AI agents connected to CRM or similar record systems should review how those agents process externally submitted data and what backend permissions they hold, since the disclosed pattern is not unique to Salesforce Agentforce according to the researchers.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Zenity Labs reported the vulnerabilities to Salesforce in June, giving the vendor roughly two months before Salesforce fully fixed the URL redaction bypass on August 18. The public disclosure, published September 24, comes after that remediation. The SalesBleed chain relied on three elements the researchers say sit together in many agent deployments: untrusted input via Web-to-Lead forms, an agent that treats record content as instructions and can render links or images, and backend tool permissions reaching sensitive data. The researchers demonstrated the risk by exfiltrating company names and deal sizes using DNS-based techniques that evaded Salesforce's Trusted URLs controls.

For readers outside security engineering, the significance is less about Salesforce specifically and more about a class of AI agents that are given access to both external inputs and sensitive internal systems. Zenity's report describes the payload as capable of querying anything a subagent's Query Records tool can reach, which in a typical General CRM deployment includes accounts and contacts. That breadth is what turns an otherwise ordinary record processing step into a potential exfiltration path.

Whether similar exposures are found elsewhere hinges on whether other agent platforms also combine externally submitted records, rich content rendering, and broad tool permissions without adequate separation. Organizations deploying such agents may need to examine which inputs are trusted and what data their agents can reach. The body does not specify what additional steps, if any, Salesforce or Zenity have planned beyond the August 18 fix.

FAQ
What is SalesBleed?
SalesBleed is the name Zenity Labs gave to an attack chain that used hidden prompt injection payloads in public Web-to-Lead forms to hijack Salesforce Agentforce agents and exfiltrate CRM data.
Did Salesforce fix the vulnerabilities?
Yes, Salesforce fully fixed the URL redaction bypass, which remediated the issues, on August 18, after Zenity reported them in June.
Does this affect only Salesforce Agentforce?
Zenity researchers said the underlying risk pattern is not unique to Agentforce. Any AI agent reading untrusted external records, rendering rich content back to users, and holding sensitive tool access has the same three ingredients.
Top Companies AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Tesla's Ara bot forecast: FSD V15, Unsupervised driving soonTop Companies AI · 3h ago
  • Disney taps Karandeep Anand as first-ever CTOTop Companies AI · 3h ago
  • ServiceNow's Amit Zavery: AI flattens silos, models commoditizeTop Companies AI · 3h ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleMcKinsey: Japan suppliers can cover almost all humanoid robot parts