Rogue Agent Watch › Records › forcedleak-salesforce-agentforce
ForcedLeak — indirect prompt injection in Salesforce Agentforce
Disclosed · added to the index · last updated
Grades
- Verification status
- Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.
Summary
Noma Security disclosed "ForcedLeak" (CVSS 9.4) in September 2025 — a critical indirect prompt-injection chain in Salesforce Agentforce. Malicious instructions submitted through a public Web-to-Lead form were later executed when an employee had the AI agent process the lead, enabling exfiltration of CRM data. The chain abused an expired, re-registerable domain that had been on Salesforce's content-security allowlist. Salesforce remediated it by enforcing a trusted-URL allowlist for Agentforce and Einstein AI.
Impact as stated
Demonstrated exfiltration of CRM data from Salesforce Agentforce via a zero-interaction Web-to-Lead vector. Researcher discovery; no in-the-wild exploitation reported. Remediated by Salesforce.
Facts as stated by sources
- Actor
- Noma Security (Noma Labs) (Researcher)
- Category
- Agent hijack / prompt injection
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Exfiltration
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051.001, AML.T0057
- OWASP LLM Top 10
- LLM01
Mitigations as stated
- Salesforce re-secured the expired allowlisted domain and enforced a Trusted URLs allowlist for Agentforce and Einstein AI.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
Sources (3)
- ForcedLeak: AI Agent risks exposed in Salesforce Agentforce
Noma Security · First-party disclosure · · archived copy - Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
The Hacker News · News · · archived copy - ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection
Security Affairs · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "forcedleak-salesforce-agentforce". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/forcedleak-salesforce-agentforce.json — CC BY-SA 4.0.