Organizations/platform

Salesforce

Maker of Agentforce and Slack.

2 records2 attackWebsite
Sep 25, 2025
ForcedLeak: Web-to-Lead prompt injection could make Salesforce Agentforce leak CRM data
AttackVulnerability disclosureNoma Security, Salesforce

Noma Security reports that instructions submitted through a public Web-to-Lead form could later steer Agentforce to send CRM data to a domain on Salesforce's allowlist that had expired and could be re-registered. Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 2025-09-08 and re-secured the domain; Noma rates the chain CVSS 9.4.

Aug 20, 2024
PromptArmor reports Slack AI can be steered to leak private-channel data via public-channel messages
AttackVulnerability disclosurePromptArmor, Salesforce

PromptArmor reports that instructions posted in a public Slack channel could be pulled into Slack AI answers for other users, enabling phishing links and leakage of data from private channels the attacker cannot read. The firm notes Slack's 2024-08-14 change to ingest files widened the surface, and that Slack described the underlying public-channel search as intended behavior.