Noma Security reports that instructions submitted through a public Web-to-Lead form could later steer Agentforce to send CRM data to a domain on Salesforce's allowlist that had expired and could be re-registered. Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 2025-09-08 and re-secured the domain; Noma rates the chain CVSS 9.4.
Why it matters
Stale allowlist entries turned a trusted exfiltration path into an attacker-controlled one.
Key facts
As stated in the sources, with where to find them.
- Reported 2025-07-28; acknowledged 2025-07-31; Trusted URLs enforcement 2025-09-08; disclosed 2025-09-25.Timeline
Findings that cite this record
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
Sources
Related records
Oct 31, 2025
Oct 8, 2025
Aug 20, 2025
Aug 6, 2025
Aug 20, 2024
Feb 13, 2026