Rogue Agent Watch › Records › forcedleak-salesforce-agentforce

ForcedLeak — indirect prompt injection in Salesforce Agentforce

Disclosed · added to the index · last updated

Grades

Verification status
Reported — Publicly reported but not independently confirmed. Never present a reported incident as confirmed.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.

Summary

Noma Security disclosed "ForcedLeak" (CVSS 9.4) in September 2025 — a critical indirect prompt-injection chain in Salesforce Agentforce. Malicious instructions submitted through a public Web-to-Lead form were later executed when an employee had the AI agent process the lead, enabling exfiltration of CRM data. The chain abused an expired, re-registerable domain that had been on Salesforce's content-security allowlist. Salesforce remediated it by enforcing a trusted-URL allowlist for Agentforce and Einstein AI.

Impact as stated

Demonstrated exfiltration of CRM data from Salesforce Agentforce via a zero-interaction Web-to-Lead vector. Researcher discovery; no in-the-wild exploitation reported. Remediated by Salesforce.

Facts as stated by sources

Actor
Noma Security (Noma Labs) (Researcher)
Category
Agent hijack / prompt injection
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Exfiltration
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051.001, AML.T0057
OWASP LLM Top 10
LLM01

Mitigations as stated

  • Salesforce re-secured the expired allowlisted domain and enforced a Trusted URLs allowlist for Agentforce and Einstein AI.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (3)

  1. ForcedLeak: AI Agent risks exposed in Salesforce Agentforce
    Noma Security · First-party disclosure · · archived copy
  2. Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
    The Hacker News · News · · archived copy
  3. ForcedLeak flaw in Salesforce Agentforce exposes CRM data via Prompt Injection
    Security Affairs · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "forcedleak-salesforce-agentforce". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/forcedleak-salesforce-agentforce.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction