On September 24, 2026, Zenity Labs researchers Alex Apostolov, Joao Donato, Avishai Efrat and Ayush RoyChowdhury published SalesBleed, a chain of three now-fixed weaknesses in Salesforce Agentforce. An outside attacker who never logs in to the victim’s Salesforce tenant submits an ordinary-looking lead through the company’s public, unauthenticated Web-to-Lead form, with instructions hidden in one of the fields. The lead sits in the database until an employee asks Agentforce about recent leads; the agent then reads the planted text as part of a legitimate request and follows it.
In Zenity’s demonstration the injected instructions had the agent query the Accounts table, which the user had not asked for, and pack the results into a URL. Two flaws in Salesforce’s Trusted URLs redaction let that URL survive: the redactor only recognised a fixed list of top-level domains, so a .fun domain passed, and it disagreed with the browser about where a URL ends, so curly braces and square brackets slipped through. When the agent’s answer rendered in the browser or in Slack, the client resolved the attacker’s hostname and the stolen data left in the DNS lookup itself, with no HTTP request to the attacker and no click by the user. Zenity reported the issues on June 1, Salesforce acknowledged them on June 2, and the fixes were confirmed in mid-August; Salesforce says it hardened the Trusted URLs mechanism.
Why it matters: it is a clean example of the combination security researchers keep warning about in enterprise agents - untrusted input anyone on the internet can write, access to private data, and an output channel that can carry data out. Each piece is a standard product feature; together they turn a marketing form into a data exfiltration path into the CRM, for a product Salesforce is selling as the centre of its AI strategy.
What it does not show: no exploitation in the wild was reported, all three issues were fixed before disclosure, and no CVE was assigned. The demonstration depends on an employee later asking the agent about leads and on the agent having access to the targeted records.