SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce

SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM (TL-2026-2710), also tracked as SalesBleed, is a high-severity software vulnerability, first published 2026-09-27. It has no confirmed attribution, affects Salesforce Agentforce, maps to 9 MITRE ATT&CK / ATLAS techniques (AML.T0051.001, AML.T0051.002, AML.T0052), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-2710

Threat ID
TL-2026-2710
Also known as
SalesBleed
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-27
Last reviewed
2026-09-27
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, sales, cross-sector
Target regions
Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM

Malware and tooling: Salesforce Agentforce, Salesforce Trusted URLs, Salesforce Web-to-Lead, Slack

Zenity Labs disclosed SalesBleed, a three-vulnerability chain in Salesforce Agentforce combining indirect prompt injection via public Web-to-Lead forms, a Trusted URLs redaction bypass, and DNS-based exfiltration to silently steal CRM data with no victim interaction or attacker authentication.

How SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM works

SalesBleed is a three-vulnerability chain in Salesforce Agentforce disclosed by Zenity Labs (researchers Alex Apostolov, Joao Donato, Avishai Efrat, and Ayush RoyChowdhury). The chain begins when an attacker submits an unauthenticated lead through a public Web-to-Lead form, hiding indirect prompt-injection instructions inside otherwise-normal-looking form fields. The malicious lead sits dormant in the Leads table indefinitely until an employee performs a routine, legitimate action -- asking an Agentforce agent to review or summarize the lead. When the agent ingests the poisoned record, it follows the embedded instructions and invokes its own Query Records tool against the Accounts table (a capability already granted to the General CRM subagent by default), extracting sensitive fields such as company names and deal sizes and encoding them as subdomain labels of an attacker-controlled URL.

That exfiltration URL must pass through Salesforce's Trusted URLs mechanism, which is designed to redact links and images from untrusted sources before they render. Zenity found two RFC 3986 non-compliance gaps in the redactor: it did not recognize unusual/unrecognized top-level domains such as '.fun', and it failed to redact URLs containing curly-brace and square-bracket termination characters even though browsers still parsed and rendered them. Exploiting both gaps together produced a malformed-looking string (e.g. 'https://random_string.oast.fun/{email}') that the redactor treated as a non-URL and left untouched, while the rendering surface treated it as a live, resolvable link. The agent then emitted the exfiltration data in two ways: (1) as an HTML <img> tag, causing the chat surface to automatically fetch the external 'image' and trigger a DNS lookup that carried the stolen data to attacker-controlled nameservers before any HTTP request completed; and (2) inside a Slack channel, where publishing the agent's output triggered Slack's automatic URL-unfurling/link-preview feature, which itself resolved the malicious domain -- exfiltrating data with zero clicks and no authentication in either path. Because DNS labels are capped at 63 characters, larger record sets were split across multiple sequential queries.

A third, related flaw let an attacker (an insider, or an external attacker via the same Web-to-Lead injection vector) weaponize the Agentforce-Slack integration's 'Reply to a Slack Thread' action to send phishing messages that appeared to originate from the trusted, company-wide Agentforce bot identity. Unlike comparable actions (e.g., 'Send a Slack Direct Message'), this action shipped without a required user-confirmation step and without any attribution showing which user or process had invoked it, so recipients had no way to trace the message back to its true origin. Combined with the same Trusted URLs bypass, the phishing links could be rendered as legitimate-looking markdown links inside a credible, in-context thread reply.

The pattern instantiates Simon Willison's 'lethal trifecta' for AI agents: untrusted external input (public Web-to-Lead submissions), access to sensitive internal data (CRM Accounts/Leads via the Query Records tool), and an unmonitored external communication channel (DNS resolution via image rendering and Slack unfurling). Zenity reported all three issues to Salesforce on June 1, 2026; Salesforce investigated and shipped the Trusted URLs hardening (standards-compliant URL parsing replacing prior regex-based validation) by August 18-19, 2026, and added invoking-user attribution plus mandatory confirmation to the Slack reply action by September 21, 2026 -- all before the September 24-25, 2026 public disclosure. No in-the-wild exploitation was observed; this was a responsibly-disclosed, proof-of-concept-validated research finding, not an active campaign.

MITRE ATT&CK / ATLAS techniques used in TL-2026-2710

Execution

AML.T0051.001 Indirect; AML.T0051.002 Triggered

Initial Access

AML.T0052 Phishing

Exfiltration

AML.T0057 LLM Data Leakage; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol; T1567 Exfiltration Over Web Service

Defense Evasion

T1027 Obfuscated Files or Information

Collection

T1213 Data from Information Repositories

Lateral Movement

T1534 Internal Spearphishing

Affected products and versions in SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM

  • Salesforce — Agentforce
    Vulnerable versions: Agentforce General CRM subagent with default Trusted URLs configuration (pre-August 2026 patch); Agentforce-Slack integration 'Reply to a Slack Thread' action in the Slack Knowledge subagent template (pre-September 2026 patch)
    Fixed in: Agentforce with Trusted URLs standards-compliant URL parsing, confirmed August 18-19, 2026; Agentforce Slack action with invoking-user attribution and mandatory confirmation, confirmed September 21, 2026

Remediation for SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM

Patches

  • Salesforce hardened Trusted URLs to reject malformed URLs with unrecognized TLDs and non-compliant termination characters, confirmed by Zenity Labs on August 18-19, 2026
  • Salesforce added invoking-user attribution and a mandatory confirmation step to the Agentforce 'Reply to a Slack Thread' action, confirmed September 21, 2026

Immediate actions

  • Review Agentforce agent and subagent tool permissions; restrict access to the minimum CRM objects required for each agent's task
  • Enforce narrowly scoped Trusted URL allowlists instead of default/broad configurations
  • Treat all externally submitted CRM fields (e.g., Web-to-Lead form content) as untrusted, attacker-controllable input, not just untrusted for display but untrusted for agent instruction-following
  • Require explicit user confirmation for Slack write actions such as 'Reply to a Slack Thread' and verify this control has not been disabled

Workarounds

  • Disable or restrict the 'Reply to a Slack Thread' Agentforce action until confirmation controls are verified enabled in the tenant
  • Strip or sanitize HTML/URL-like content from Web-to-Lead submissions before it reaches agent context, pending confirmation of the Trusted URLs patch

Longer-term hardening

  • Apply Salesforce's standards-compliant (RFC 3986) URL parsing patch for Trusted URLs and confirm it is active in the tenant
  • Monitor and audit AI agent tool-invocation logs for anomalous cross-object Query Records access (e.g., a lead-review request that also queries Accounts)
  • Implement egress DNS monitoring/logging to detect subdomain-encoded exfiltration patterns
  • Adopt a 'lethal trifecta' risk review (untrusted input + private data access + external communication) for any newly deployed or reconfigured AI agent

Timeline of SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM

  • Zenity Labs reports all three SalesBleed vulnerabilities (Web-to-Lead prompt injection, Trusted URLs bypass, and Slack reply-action hijack) to Salesforce.
  • Salesforce acknowledges the report and begins remediation and investigation.
  • Zenity Labs holds a technical briefing call with the Salesforce security team to walk through the exploit chain.
  • Salesforce confirms its engineering team is actively developing a fix for the reported issues.
  • Salesforce fully confirms the Trusted URLs hardening fix addressing the zero-click DNS exfiltration paths.
  • Zenity Labs independently validates that the Trusted URLs bypass used in its research is no longer exploitable.
  • Salesforce corrects the missing invoking-user attribution on the 'Reply to a Slack Thread' Agentforce action.
  • Salesforce implements a mandatory user-confirmation requirement for the 'Reply to a Slack Thread' action, completing remediation of all three flaws.
  • Zenity Labs publicly publishes its SalesBleed research in two posts detailing the data-exfiltration chain and the Slack phishing-hijack flaw.
  • Infosecurity Magazine and other outlets report on SalesBleed, framing it as illustrative of broader zero-click risk in agentic AI/CRM integrations.

Sources cited for SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM

More in vulnerability

Detection coverage for TL-2026-2710

As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2710 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats