Chronicle/Attacks & incidents

ForcedLeak: Web-to-Lead prompt injection could make Salesforce Agentforce leak CRM data

AttackVulnerability disclosureSignificance assistant-drafted

Noma Security reports that instructions submitted through a public Web-to-Lead form could later steer Agentforce to send CRM data to a domain on Salesforce's allowlist that had expired and could be re-registered. Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 2025-09-08 and re-secured the domain; Noma rates the chain CVSS 9.4.

Why it matters

Stale allowlist entries turned a trusted exfiltration path into an attacker-controlled one.

Key facts

As stated in the sources, with where to find them.

  • Reported 2025-07-28; acknowledged 2025-07-31; Trusted URLs enforcement 2025-09-08; disclosed 2025-09-25.Timeline

Findings that cite this record

Key questions this bears on

Sources

Related records