Zenity Labs today disclosed SalesBleed, a set of three security vulnerabilities in Salesforce Agentforce that could allow a single untrusted lead to hijack trusted Agentforce agents, silently exfiltrate sensitive CRM data and turn an enterprise agent into a vehicle for delivering elaborate phishing attacks. The flaws allow attackers to silently extract sensitive Salesforce data and abuse trusted enterprise AI agents for phishing without requiring an employee click.
Disclosed in New York, the research found multiple weaknesses in Trusted URLs, the Salesforce security mechanism designed to prevent Agentforce from sending enterprise data to unapproved destinations, and a separate flaw in the Agentforce-Slack integration.
Zenity Labs found multiple weaknesses in Trusted URLs, the Salesforce security mechanism designed to prevent Agentforce from displaying URLs and images from untrusted sources. The researchers demonstrated that those weaknesses could be abused to send sensitive data to unapproved destinations.
“This isn’t one clever bypass or a single misconfiguration. We found multiple ways to break through the security boundary designed to stop Agentforce from sending enterprise data to unapproved destinations,” said Michael Bargury, co-founder and CTO of Zenity. “Hard boundaries remain one of the strongest tools we have for containing AI agents, but they are still software. When those controls fail, we are left with a privileged access agent with high autonomy and no bounds.”
One attack chain begins with nothing more than a Web-to-Lead form. Web-to-Lead is Salesforce's official mechanism for collecting leads and creates a direct path for outside information to enter the Salesforce CRM. As Zenity Labs demonstrated at Black Hat 2025, when Agentforce processes that information, the same pathway can become an attack vector. Attackers can plant malicious instructions in a Web-to-Lead submission that remain dormant until an employee later asks an Agentforce agent an ordinary question about leads.
1. Zero-click CRM data exfiltration: Agentforce reported that the content had been blocked by the organization’s security policies, even though the sensitive CRM data had already been transmitted to the attacker-controlled server. Trusted URLs are designed to restrict external destinations and redact links or images pointing to unapproved domains. Zenity Labs found multiple weaknesses, including top-level domains the mechanism failed to recognize and character sequences that interfered with URL parsing. Those weaknesses allowed malicious instructions to cause Agentforce to query Salesforce records and embed retrieved information in image requests to an attacker-controlled server. When the response renders, the image requests automatically transmit embedded CRM data with no click.
2. Zero-click data exfiltration through Slack: The second vulnerability uses Slack’s URL unfurling functionality. Slack automatically retrieves information from links to generate previews, and specially constructed links can cause Slack to initiate requests that carry CRM data to attacker-controlled infrastructure as soon as links appear. No malicious link needs to be clicked for CRM data to leave the environment.
3. Trusted AI agent impersonation and phishing: The third vulnerability involves Agentforce's integration with Slack. Agentforce agents can join channels, read messages and send messages when prompted. Zenity Labs found that the integration allowed an agent to send messages to different channels without reliably identifying the user who initiated the action. An insider could exploit the flaw to post phishing messages under the trusted agent's identity while remaining anonymous. An external attacker could also achieve similar result through indirect prompt injection.
For enterprises deploying AI agents, the concern is not just what the agent can access, but how well the controls designed to contain it actually work. Trusted URLs are intended to act as a hard security boundary between Agentforce and unapproved external destinations.
“We need to think beyond whether an agent has guardrails and ask what happens when those guardrails are bypassed,” Bargury said. “Security teams need layered visibility into what agents access, which tools they invoke and what actions they take. Even with limited access and hard defense mechanisms in place, close monitoring remains essential. As the threat presented by AI agents becomes more autonomous, a single design flaw can lead to very unexpected consequences.”
The findings were disclosed to Salesforce on June 1, 2026. Salesforce responded quickly and worked directly with the research team to investigate the issues, addressing the specific Trusted URLs bypasses reported by Zenity Labs within approximately two weeks. The attribution issue identified in the Slack research was also remediated.
Zenity Labs published technical research detailing the findings including SalesBleed: Indirect Prompt Injection and 0-Click Data Exfiltration on Agentforce and SalesBleed: Hijacking Agentforce in Slack for Anonymous Phishing Attacks.
About Zenity
Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security.