{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/noma-forcedleak-salesforce-agentforce-2025/",
 "asOf": "2026-09-26",
 "id": "noma-forcedleak-salesforce-agentforce-2025",
 "date": "2025-09-25",
 "datePrecision": "day",
 "title": "ForcedLeak: Web-to-Lead prompt injection could make Salesforce Agentforce leak CRM data",
 "lane": "attack",
 "kind": "vulnerability-disclosure",
 "summary": "Noma Security reports that instructions submitted through a public Web-to-Lead form could later steer Agentforce to send CRM data to a domain on Salesforce's allowlist that had expired and could be re-registered. Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 2025-09-08 and re-secured the domain; Noma rates the chain CVSS 9.4.",
 "whyItMatters": "Stale allowlist entries turned a trusted exfiltration path into an attacker-controlled one.",
 "actors": [
  "noma-security",
  "salesforce"
 ],
 "topics": [
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools"
 ],
 "artifacts": [],
 "sources": [
  {
   "url": "https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce",
   "publisher": "Noma Security",
   "title": "ForcedLeak: AI agent risks exposed in Salesforce Agentforce",
   "date": "2025-09-25",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Reported 2025-07-28; acknowledged 2025-07-31; Trusted URLs enforcement 2025-09-08; disclosed 2025-09-25.",
   "locator": "Timeline"
  }
 ],
 "significance": 3,
 "fideQuestions": [],
 "methods": [
  "capability-restriction",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}