Threat
Salesforce Agentforce Zero-Click Data Exfiltration Risks
First reported · Discovered aisecmaster.com
Page published
Earliest dated coverage: 26 Sep 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 26 Sep 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
SalesBleed shows that an autonomous AI agent with legitimate access to business records can be weaponized through ordinary-looking customer-submitted content, turning indirect prompt injection into silent, zero-click exfiltration of sensitive CRM data.
Zenity Labs disclosed SalesBleed, a zero-click attack chain against Salesforce Agentforce in which hidden indirect prompt-injection payloads submitted via Web to Lead are later processed by an Agentforce agent, then combined with weaknesses in Salesforce Trusted URL handling to exfiltrate CRM data to an attacker-controlled destination without any victim click or authentication.