Salesforce customers have been urged to patch immediately after cybersecurity researchers at Noma Labs uncovered a severe vulnerability in the Agentforce AI platform that could allow threat actors to siphon sensitive customer information.
Dubbed ForcedLeak, the flaw impacts Salesforce’s Web-to-Lead functionality and carries a CVSS score of 9.4, indicating maximum severity.
The Web-to-Lead feature enables the automatic capture of prospect information through online forms at conferences and marketing campaigns.
Attackers exploit ForcedLeak to embed malicious instructions within apparently benign lead submissions.
When employees later query Agentforce about captured data, the AI agent inadvertently executes these hidden commands.
Unlike conventional chatbots, Agentforce is an autonomous AI agent engineered to reason, plan, and execute complex workflows.
Its expanded capabilities, spanning knowledge bases, internal memory, connected tools, and external systems, introduce a substantially larger attack surface.
ForcedLeak leverages indirect prompt injection, inserting multi-step instructions into data that the AI interprets as legitimate.
Noma Labs researchers identified the Description field of the Web-to-Lead form as the optimal injection vector due to its generous 42,000-character limit.
The exploit chain hinges on three critical weaknesses:
my-salesforce-cms.com) persisted in Salesforce’s configuration, allowing exfiltrated data to be transmitted to an attacker-controlled endpoint.The expired domain’s trusted status was exploited to establish covert channels, enabling attackers to receive stolen customer contact details, sales pipeline records, internal communications, and historical interaction logs.
Organizations leveraging Salesforce Agentforce within sales, marketing, and customer acquisition workflows face an acute risk of data compromise.
Upon notification in July 2025, Salesforce launched an immediate investigation and issued patches by September 2025. Key mitigation steps include:
This incident underscores the unique security challenges posed by AI agents within enterprise environments.
Traditional threat modeling and controls fall short when AI systems autonomously process complex instructions.
As AI integration in business workflows accelerates, organizations must adopt AI-centric security frameworks that encompass prompt hygiene, memory sanitization, and continuous model behavior monitoring to guard against novel attack vectors.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant Updates
The post Critical Flaw in Salesforce AI Agent Enables Data Exfiltration appeared first on Cyber Security News.
Border Beam Vanilla is a Vanilla JavaScript library that decorates DOM elements with animated traveling…
ctree.js is a fun little JavaScript library that generates a colorful Christmas tree right in…
A comprehensive review of browser privacy in 2026 reveals that Google Chrome remains highly vulnerable…
DETROIT, MI (WOWO) A competitive shift is underway on the Detroit River as the operator…
The European Commission’s newly launched Digital Age Verification App, unveiled on April 14, 2026, to…
MUNCIE, IND. (WOWO) A Muncie man is facing felony charges after police say he assaulted…
This website uses cookies.