Salesforce's Agentforce Vulnerability Exposes Critical AI Security Flaw

Reviewed byNidhi Govil

3 Sources

Share

A critical vulnerability in Salesforce's Agentforce AI platform, dubbed 'ForcedLeak', allowed potential data theft through prompt injection. The flaw, now patched, highlights the evolving security challenges in AI-integrated business tools.

Salesforce's Agentforce Vulnerability Exposes Critical AI Security Flaw

Security researchers at Noma discovered 'ForcedLeak', a critical prompt injection vulnerability in Salesforce's Agentforce AI platform, enabling potential data theft from autonomous business agents

1

.

Source: The Hacker News

Source: The Hacker News

The ForcedLeak Mechanism and Attack

Rated 9.4/10 CVSS, ForcedLeak exploits the AI's inability to differentiate legitimate data from malicious commands. Attackers leveraged Salesforce's Web-to-Lead feature, inserting malicious instructions disguised as text into the description field. By acquiring an expired Salesforce-related domain (my-salesforce-cms.com), they tricked the AI agent into querying the CRM for sensitive lead data and exfiltrating it to their controlled server

2

. This technique weaponizes prompt injection, creating dangerous trust boundary confusion.

Severe Data Exposure and Salesforce's Response

A successful ForcedLeak attack could have exposed extensive confidential data, including internal communications, business strategies, employee/customer PII, interaction records, and transactional details. Noma's co-founder Alon Tron termed a successful compromise "game over," highlighting its severity

3

. Salesforce rapidly re-secured the expired domain, patched Agentforce and Einstein AI agents to prevent output to untrusted URLs, and implemented a URL allowlist mechanism

2

.

Broader AI Security Implications

This vulnerability underscores escalating security challenges in AI-integrated business tools. It shows how human-AI interfaces become social engineering targets and how traditional security controls fall short when user instructions mix with external data. ForcedLeak reinforces the urgent need for proactive AI security and new paradigms to protect against evolving threats as AI systems become more deeply embedded in operations

1

.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo