# SalesBleed: zero-click CRM data theft through Salesforce Agentforce

> A hidden instruction in a public lead form turned a CRM agent into a silent data leak.

- **Severity:** Medium: Real and reproducible, but needs unusual setup, user help or a narrow audience. Plan a fix.
- **Category:** Attack, Vulnerability
- **Published by:** Zenity Labs
- **Disclosed:** 2026-09-24
- **Affects:** Salesforce Agentforce, Agentforce in Slack
- **Research by:** Alex Apostolov, João Donato, Avishai Efrat, Ayush RoyChowdhury
- **Primary source:** https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce
- **Page:** https://theinjection.dev/items/zenity-salesbleed-agentforce-exfiltration/

SalesBleed is a Zenity Labs attack in which one web form lead carrying a prompt injection made Salesforce Agentforce leak Accounts data through DNS with zero clicks. Salesforce hardened its Trusted URLs filter in August 2026.

## What happened

Zenity Labs published SalesBleed on September 24, 2026, describing how an unauthenticated attacker could hijack Salesforce Agentforce and pull CRM data out with zero clicks. Zenity reported it to Salesforce on June 1, 2026, and validated the fix on August 19, 2026.

## How it works

The attacker submits a lead through the public Web-to-Lead form with hidden instructions. When an employee asks the agent about recent leads, it reads the injection, queries the Accounts table with its Query Records tool and builds an image URL whose subdomain carries the data. The URL slipped past the Trusted URLs redactor because it used an unrecognized top-level domain and characters like curly braces, and the browser's image load sent a DNS query to the attacker's nameserver. A second part shows the agent's Slack reply action could be used for anonymous phishing.

## Who is affected

Salesforce customers running Agentforce with the general CRM subagent, which in the default setup could read both Leads and Accounts. Salesforce says it has hardened the Trusted URLs mechanism.

## What to do

Treat Web-to-Lead and other public inputs as untrusted data, scope each subagent to the tables it needs, and review agent actions that write or send messages without confirmation.

## Sources

1. [Zenity Part 1](https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce)
2. [Zenity Part 2: Slack](https://labs.zenity.io/post/salesbleed-hijacking-agentforce-in-slack-for-anonymous-phishing)
