SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM Data Exfiltration in Salesforce Agentforce
SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM (TL-2026-2710), also tracked as SalesBleed, is a high-severity software vulnerability, first published 2026-09-27. It has no confirmed attribution, affects Salesforce Agentforce, maps to 9 MITRE ATT&CK / ATLAS techniques (AML.T0051.001, AML.T0051.002, AML.T0052), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-2710
- Threat ID
- TL-2026-2710
- Also known as
- SalesBleed
- Severity
- HIGH
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-27
- Last reviewed
- 2026-09-27
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, sales, cross-sector
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM
Malware and tooling: Salesforce Agentforce, Salesforce Trusted URLs, Salesforce Web-to-Lead, Slack
Zenity Labs disclosed SalesBleed, a three-vulnerability chain in Salesforce Agentforce combining indirect prompt injection via public Web-to-Lead forms, a Trusted URLs redaction bypass, and DNS-based exfiltration to silently steal CRM data with no victim interaction or attacker authentication.
How SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM works
SalesBleed is a three-vulnerability chain in Salesforce Agentforce disclosed by Zenity Labs (researchers Alex Apostolov, Joao Donato, Avishai Efrat, and Ayush RoyChowdhury). The chain begins when an attacker submits an unauthenticated lead through a public Web-to-Lead form, hiding indirect prompt-injection instructions inside otherwise-normal-looking form fields. The malicious lead sits dormant in the Leads table indefinitely until an employee performs a routine, legitimate action -- asking an Agentforce agent to review or summarize the lead. When the agent ingests the poisoned record, it follows the embedded instructions and invokes its own Query Records tool against the Accounts table (a capability already granted to the General CRM subagent by default), extracting sensitive fields such as company names and deal sizes and encoding them as subdomain labels of an attacker-controlled URL.
That exfiltration URL must pass through Salesforce's Trusted URLs mechanism, which is designed to redact links and images from untrusted sources before they render. Zenity found two RFC 3986 non-compliance gaps in the redactor: it did not recognize unusual/unrecognized top-level domains such as '.fun', and it failed to redact URLs containing curly-brace and square-bracket termination characters even though browsers still parsed and rendered them. Exploiting both gaps together produced a malformed-looking string (e.g. 'https://random_string.oast.fun/{email}') that the redactor treated as a non-URL and left untouched, while the rendering surface treated it as a live, resolvable link. The agent then emitted the exfiltration data in two ways: (1) as an HTML <img> tag, causing the chat surface to automatically fetch the external 'image' and trigger a DNS lookup that carried the stolen data to attacker-controlled nameservers before any HTTP request completed; and (2) inside a Slack channel, where publishing the agent's output triggered Slack's automatic URL-unfurling/link-preview feature, which itself resolved the malicious domain -- exfiltrating data with zero clicks and no authentication in either path. Because DNS labels are capped at 63 characters, larger record sets were split across multiple sequential queries.
A third, related flaw let an attacker (an insider, or an external attacker via the same Web-to-Lead injection vector) weaponize the Agentforce-Slack integration's 'Reply to a Slack Thread' action to send phishing messages that appeared to originate from the trusted, company-wide Agentforce bot identity. Unlike comparable actions (e.g., 'Send a Slack Direct Message'), this action shipped without a required user-confirmation step and without any attribution showing which user or process had invoked it, so recipients had no way to trace the message back to its true origin. Combined with the same Trusted URLs bypass, the phishing links could be rendered as legitimate-looking markdown links inside a credible, in-context thread reply.
The pattern instantiates Simon Willison's 'lethal trifecta' for AI agents: untrusted external input (public Web-to-Lead submissions), access to sensitive internal data (CRM Accounts/Leads via the Query Records tool), and an unmonitored external communication channel (DNS resolution via image rendering and Slack unfurling). Zenity reported all three issues to Salesforce on June 1, 2026; Salesforce investigated and shipped the Trusted URLs hardening (standards-compliant URL parsing replacing prior regex-based validation) by August 18-19, 2026, and added invoking-user attribution plus mandatory confirmation to the Slack reply action by September 21, 2026 -- all before the September 24-25, 2026 public disclosure. No in-the-wild exploitation was observed; this was a responsibly-disclosed, proof-of-concept-validated research finding, not an active campaign.
MITRE ATT&CK / ATLAS techniques used in TL-2026-2710
Execution
AML.T0051.001 Indirect; AML.T0051.002 Triggered
Initial Access
AML.T0052 Phishing
Exfiltration
AML.T0057 LLM Data Leakage; T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol; T1567 Exfiltration Over Web Service
Defense Evasion
T1027 Obfuscated Files or Information
Collection
T1213 Data from Information Repositories
Lateral Movement
Affected products and versions in SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM
- Salesforce — Agentforce
Vulnerable versions: Agentforce General CRM subagent with default Trusted URLs configuration (pre-August 2026 patch); Agentforce-Slack integration 'Reply to a Slack Thread' action in the Slack Knowledge subagent template (pre-September 2026 patch)
Fixed in: Agentforce with Trusted URLs standards-compliant URL parsing, confirmed August 18-19, 2026; Agentforce Slack action with invoking-user attribution and mandatory confirmation, confirmed September 21, 2026
Remediation for SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM
Patches
- Salesforce hardened Trusted URLs to reject malformed URLs with unrecognized TLDs and non-compliant termination characters, confirmed by Zenity Labs on August 18-19, 2026
- Salesforce added invoking-user attribution and a mandatory confirmation step to the Agentforce 'Reply to a Slack Thread' action, confirmed September 21, 2026
Immediate actions
- Review Agentforce agent and subagent tool permissions; restrict access to the minimum CRM objects required for each agent's task
- Enforce narrowly scoped Trusted URL allowlists instead of default/broad configurations
- Treat all externally submitted CRM fields (e.g., Web-to-Lead form content) as untrusted, attacker-controllable input, not just untrusted for display but untrusted for agent instruction-following
- Require explicit user confirmation for Slack write actions such as 'Reply to a Slack Thread' and verify this control has not been disabled
Workarounds
- Disable or restrict the 'Reply to a Slack Thread' Agentforce action until confirmation controls are verified enabled in the tenant
- Strip or sanitize HTML/URL-like content from Web-to-Lead submissions before it reaches agent context, pending confirmation of the Trusted URLs patch
Longer-term hardening
- Apply Salesforce's standards-compliant (RFC 3986) URL parsing patch for Trusted URLs and confirm it is active in the tenant
- Monitor and audit AI agent tool-invocation logs for anomalous cross-object Query Records access (e.g., a lead-review request that also queries Accounts)
- Implement egress DNS monitoring/logging to detect subdomain-encoded exfiltration patterns
- Adopt a 'lethal trifecta' risk review (untrusted input + private data access + external communication) for any newly deployed or reconfigured AI agent
Timeline of SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM
- Zenity Labs reports all three SalesBleed vulnerabilities (Web-to-Lead prompt injection, Trusted URLs bypass, and Slack reply-action hijack) to Salesforce.
- Salesforce acknowledges the report and begins remediation and investigation.
- Zenity Labs holds a technical briefing call with the Salesforce security team to walk through the exploit chain.
- Salesforce confirms its engineering team is actively developing a fix for the reported issues.
- Salesforce fully confirms the Trusted URLs hardening fix addressing the zero-click DNS exfiltration paths.
- Zenity Labs independently validates that the Trusted URLs bypass used in its research is no longer exploitable.
- Salesforce corrects the missing invoking-user attribution on the 'Reply to a Slack Thread' Agentforce action.
- Salesforce implements a mandatory user-confirmation requirement for the 'Reply to a Slack Thread' action, completing remediation of all three flaws.
- Zenity Labs publicly publishes its SalesBleed research in two posts detailing the data-exfiltration chain and the Slack phishing-hijack flaw.
- Infosecurity Magazine and other outlets report on SalesBleed, framing it as illustrative of broader zero-click risk in agentic AI/CRM integrations.
Sources cited for SalesBleed: Indirect Prompt Injection Enables Zero-Click CRM
- SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce
- SalesBleed: Hijacking Agentforce in Slack for Anonymous Phishing
- Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk
- Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
- Salesforce Indirect Prompt Injection Vulnerability Enables 0-click Data Exfiltration
- Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection
- Zenity Labs Uncovers SalesBleed, 3 Salesforce Agentforce Flaws Enabling Zero-Click CRM Data Theft and AI Agent Impersonation
- The lethal trifecta for AI agents: private data, untrusted content, and external communication
More in vulnerability
- CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- Comment2Shell: Unauthenticated Stored XSS-to-RCE Chain in WordPress wpautop() (CVE-2026-93485)
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)
Detection coverage for TL-2026-2710
As of 2026-09-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2710 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.