3 Sources
[1]
Salesforce Agentforce tricked into leaking sales leads
A now-fixed flaw in Salesforce's Agentforce could have allowed external attackers to steal sensitive customer data via prompt injection, according to security researchers who published a proof-of-concept attack on Thursday. They were aided by an expired trusted domain that they were able to buy for
[2]
Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect
[3]
Salesforce Agentforce hit by Noma "ForcedLeak" exploit
Researchers at Noma uncovered a critical prompt-injection flaw called "ForcedLeak" in Salesforce's Agentforce AI agents, scoring 9.4/10 on the CVSS scale. Attackers can embed malicious prompts in standard Salesforce web forms, tricking the AI into exfiltrating sensitive CRM data to whitelisted
Share
Copy Link
A critical vulnerability in Salesforce's Agentforce AI platform, dubbed 'ForcedLeak', allowed potential data theft through prompt injection. The flaw, now patched, highlights the evolving security challenges in AI-integrated business tools.
Security researchers at Noma discovered 'ForcedLeak', a critical prompt injection vulnerability in Salesforce's Agentforce AI platform, enabling potential data theft from autonomous business agents
1
.
Source: Hacker News
Rated 9.4/10 CVSS, ForcedLeak exploits the AI's inability to differentiate legitimate data from malicious commands. Attackers leveraged Salesforce's Web-to-Lead feature, inserting malicious instructions disguised as text into the description field. By acquiring an expired Salesforce-related domain (my-salesforce-cms.com), they tricked the AI agent into querying the CRM for sensitive lead data and exfiltrating it to their controlled server
2
. This technique weaponizes prompt injection, creating dangerous trust boundary confusion.A successful ForcedLeak attack could have exposed extensive confidential data, including internal communications, business strategies, employee/customer PII, interaction records, and transactional details. Noma's co-founder Alon Tron termed a successful compromise "game over," highlighting its severity
3
. Salesforce rapidly re-secured the expired domain, patched Agentforce and Einstein AI agents to prevent output to untrusted URLs, and implemented a URL allowlist mechanism2
.Related Stories
This vulnerability underscores escalating security challenges in AI-integrated business tools. It shows how human-AI interfaces become social engineering targets and how traditional security controls fall short when user instructions mix with external data. ForcedLeak reinforces the urgent need for proactive AI security and new paradigms to protect against evolving threats as AI systems become more deeply embedded in operations
1
.Summarized by
Navi
[1]
[3]
27 Aug 2025•Technology

15 Apr 2026•Technology

10 Jun 2026•Technology

1
Policy and Regulation

2
Technology

3
Policy and Regulation
