SalesBleed: zero-click CRM data exfiltration from Salesforce Agentforce
Zenity Labs disclosed on September 24, 2026 three URL-redaction flaws that let a Web-to-Lead prompt injection leak CRM data through DNS. Salesforce fixed them on August 18.
What is this?
On September 24, 2026, Zenity Labs published SalesBleed, a set of three flaws in how Salesforce Agentforce filtered URLs in agent output. Chained with an indirect prompt injection planted through a public Web-to-Lead form, they allowed zero-click exfiltration of CRM data, with no action from the victim beyond asking the agent a routine question. Infosecurity Magazine and Salesforce Ben covered it on September 25.
Per Zenity’s timeline, the issue was reported to Salesforce on June 1, 2026, discussed with its security team on June 16, confirmed fixed on August 18, and disclosed publicly on September 24. No CVE identifier was cited in the sources reviewed.
How it works
Agentforce’s “Trusted URLs” mechanism redacts links to untrusted destinations in agent output. Zenity found three gaps between what the redactor considered a URL and what the browser actually rendered:
- The redactor recognized only a fixed set of top-level domains, so hostnames under unrecognized TLDs were not flagged.
- The redactor and the rendering surface disagreed on where a URL ends: some bracket and brace characters were not redacted but still worked in rendered output.
- Malformed URLs that violated RFC 3986 passed the redaction layer yet were still loaded by browsers as image sources.
The attack chain, at a conceptual level: an outsider submits a lead whose free-text field contains instructions. Later, an employee asks the agent about leads, and the agent reads that record as part of its context. The injected text steers the agent to query account records through its Query Records tool, embed the result in a hostname, and emit it as an image reference. When the browser tries to load the image, the DNS lookup carries the data to a server the attacker controls. Zenity’s proof of concept extracted company names and deal sizes, and notes the injection “could have asked for anything the subagent’s Query Records tool can reach.” This write-up deliberately omits payloads and exact URL forms.
Why it matters
The pattern is broader than one vendor. Any agent that (1) ingests records created by unauthenticated parties, (2) holds a data-reading tool, and (3) renders links or images has the same structure, which is sometimes called the lethal trifecta. Output redaction is a parser, and parsers that disagree with renderers create bypasses. Because the exfiltration channel is a DNS lookup triggered by rendering, it needs no click and leaves little trace in application logs.
Defenses
- Scope tools to the task. Agents that triage inbound leads should not hold broad read access to the Accounts table; apply least privilege per agent and per subagent.
- Treat unauthenticated inputs as untrusted data. Web-to-Lead and similar public intake fields should be flagged, sanitized, or kept out of the agent’s context where possible.
- Don’t rely on redaction alone. Prefer allowlisting exact destinations over blocklisting patterns, and disable automatic image or link rendering for agent output where it is not needed.
- Use one URL parser. The redactor and renderer should share the same parsing and normalization logic.
- Monitor egress. Alert on unusual DNS patterns, such as long or high-entropy subdomains from user-facing clients.
- Confirm patch status. Salesforce states the issue is remediated server-side; admins should still review which data sources their agents can read.
Status
| Item | Detail |
|---|---|
| Product | Salesforce Agentforce |
| Discoverer | Zenity Labs |
| Reported | June 1, 2026 |
| Fix confirmed | August 18, 2026 |
| Public disclosure | September 24, 2026 |
| Patch status | Fixed by vendor (Trusted URLs hardened) |
| CVE | None cited in sources |