Loading cryptocurrency prices...

Critical ‘ForcedLeak’ Flaw Hits Salesforce Agentforce AI System

Critical “ForcedLeak” Vulnerability in Salesforce Agentforce AI Exposes Sensitive CRM Data via Indirect Prompt Injection

  • A critical vulnerability, named ForcedLeak, has been discovered in Salesforce’s Agentforce AI platform.
  • The flaw could allow attackers to steal sensitive data from customer management systems using indirect prompt injection.
  • The issue affects organizations using Agentforce with Web-to-Lead functionality enabled.
  • Salesforce has secured the affected domain and released security patches, adding controls to block data leaks to untrusted destinations.
  • Users are advised to enforce stricter input validation, monitor for suspicious data, and adopt recommended security measures.

Security researchers reported a major flaw in the Salesforce Agentforce platform on July 28, 2025. The vulnerability, called ForcedLeak, could let attackers pull sensitive information from the company’s CRM by tricking the AI system through indirect prompt injection.

- Advertisement -

ForcedLeak, which received a severity score of 9.4 out of 10, threatens any company using the Agentforce platform with its Web-to-Lead form feature. The bug, discovered by Noma Security, takes advantage of the way AI agents process and respond to instructions embedded in external data.

“This vulnerability demonstrates how AI agents present a fundamentally different and expanded attack surface compared to traditional prompt-response systems,” said Sasi Levi, security research lead at Noma. According to the researchers, attackers could submit a Web-to-Lead form containing hidden instructions in the Description field. When an employee processes this lead using the AI, the system may run these malicious instructions without knowing the difference, resulting in accidental data leaks.

The attack works by transmitting stolen information to a domain previously allowed by Salesforce’s security settings. This domain had expired and was purchased by the attacker for only $5. The data was then exfiltrated as a PNG image to this domain. The process exploits weak context checking, overly broad AI model behavior, and a way around existing security policies.

Salesforce has reclaimed the expired domain and released patches to strengthen the system. Now, Agentforce and Einstein AI agents will limit content sharing to trusted URLs only, using an official allowlist.

- Advertisement -

“Our underlying services powering Agentforce will enforce the Trusted URL allowlist to ensure no malicious links are called or generated through potential prompt injection,” Salesforce said in a recent alert. The company recommends that users apply these controls, review current lead data for suspicious entries, and add stronger input validation and data cleaning steps.

Security experts view ForcedLeak as a reminder for organizations to maintain proactive AI security. Sasi Levi adds: “It serves as a strong reminder that even a low-cost discovery can prevent millions in potential breach damages.” For more information, the initial advisory is available here. More technical details can be found in Noma’s full report here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

North Korea Steals $2.84B in Crypto Amid Growing Cyber Threats

North Korea has stolen $2.84 billion in cryptocurrency during 2024.The country runs a large,...

US-China Trade Deal Progress Sparks Crypto Market Rally

The US and China have made significant progress on a trade deal framework.The deal...

AI-driven crypto payments via Coinbase protocol surge 4,300% in weekly growth – DL News

Use of the payment protocol x402, developed by Coinbase, among AI-powered agents surged sharply...

XRP Ledger’s Batch Amendment Nears Activation with NFT Trading Boost

The proposed XRP Ledger amendment called Batch (XLS-56) allows multiple transactions to be combined...

Investor Demand Soars for Teucrium’s 2x Long Daily XRP ETF

Investor interest in XRP is very high, with significant inflows since April 2025.Teucrium Trading’s...
- Advertisement -

Must Read

How to Set Up a Simple Bitcoin Tip Jar for Your Site or Stream

QUICK LINKSWhat a tip jar is, in plain wordsWhat you needBuild a payment link that just worksAdd a QR code that actually scansWhere to...