Critical ‘ForcedLeak’ Flaw Hits Salesforce Agentforce AI System

Critical “ForcedLeak” Vulnerability in Salesforce Agentforce AI Exposes Sensitive CRM Data via Indirect Prompt Injection

  • A critical vulnerability, named ForcedLeak, has been discovered in Salesforce’s Agentforce AI platform.
  • The flaw could allow attackers to steal sensitive data from customer management systems using indirect prompt injection.
  • The issue affects organizations using Agentforce with Web-to-Lead functionality enabled.
  • Salesforce has secured the affected domain and released security patches, adding controls to block data leaks to untrusted destinations.
  • Users are advised to enforce stricter input validation, monitor for suspicious data, and adopt recommended security measures.

Security researchers reported a major flaw in the Salesforce Agentforce platform on July 28, 2025. The vulnerability, called ForcedLeak, could let attackers pull sensitive information from the company’s CRM by tricking the AI system through indirect prompt injection.

- Advertisement -

ForcedLeak, which received a severity score of 9.4 out of 10, threatens any company using the Agentforce platform with its Web-to-Lead form feature. The bug, discovered by Noma Security, takes advantage of the way AI agents process and respond to instructions embedded in external data.

“This vulnerability demonstrates how AI agents present a fundamentally different and expanded attack surface compared to traditional prompt-response systems,” said Sasi Levi, security research lead at Noma. According to the researchers, attackers could submit a Web-to-Lead form containing hidden instructions in the Description field. When an employee processes this lead using the AI, the system may run these malicious instructions without knowing the difference, resulting in accidental data leaks.

The attack works by transmitting stolen information to a domain previously allowed by Salesforce’s security settings. This domain had expired and was purchased by the attacker for only $5. The data was then exfiltrated as a PNG image to this domain. The process exploits weak context checking, overly broad AI model behavior, and a way around existing security policies.

Salesforce has reclaimed the expired domain and released patches to strengthen the system. Now, Agentforce and Einstein AI agents will limit content sharing to trusted URLs only, using an official allowlist.

- Advertisement -

“Our underlying services powering Agentforce will enforce the Trusted URL allowlist to ensure no malicious links are called or generated through potential prompt injection,” Salesforce said in a recent alert. The company recommends that users apply these controls, review current lead data for suspicious entries, and add stronger input validation and data cleaning steps.

Security experts view ForcedLeak as a reminder for organizations to maintain proactive AI security. Sasi Levi adds: “It serves as a strong reminder that even a low-cost discovery can prevent millions in potential breach damages.” For more information, the initial advisory is available here. More technical details can be found in Noma’s full report here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Bitcoin Tops Gold, Oil Amid Iran War Shock

Bitcoin (BTC) surged 12.1% to $73,419 since the U.S.-Israeli military action against Iran began...

Crypto Gains Stall as Bears, Struggling Miners Weigh

Derivatives and onchain data show a lack of bullish conviction, as 43% of Bitcoin...

Nvidia’s Huang: Software Stocks Ready to Pop

NVIDIA CEO Jensen Huang contends Wall Street misunderstands software companies, believing they will benefit...

Nvidia’s OpenAI Investment Could Be Its Last Before IPO

NVIDIA CEO Jensen Huang indicated the company's recent $30 billion investment in OpenAI may...

Bitcoin Outperforms Oil, Gold in US-Iran War Shock

Bitcoin has surged 12.1% since the onset of the US-Israeli conflict with Iran, outperforming...

Must Read

Top 9 Most Legit Bitcoin Faucets

Bitcoin faucets are platforms where you can earn Bitcoin free. Some other faucet apps and websites allow users to receive different cryptocurrencies for free....
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!