Salesforce AI Agent Vulnerability Allows Let Attackers Exfiltration Sensitive Data
A critical vulnerability in Salesforce's Agentforce AI platform, identified by Noma Labs and named ForcedLeak , could have enabled external attackers to access sensitive CRM data.
A critical vulnerability in Salesforce's Agentforce AI platform, identified by Noma Labs and named ForcedLeak , could have enabled external attackers to access sensitive CRM data.
The vulnerability, with a CVSS score of 9.4, involved a sophisticated indirect prompt injection attack. This issue highlights the unique attack surface introduced by autonomous AI agents compared to traditional systems.
Upon notification, Salesforce investigated and deployed patches to prevent data transmission by Agentforce agents to untrusted URLs, mitigating the immediate risk.
The research revealed how AI agents can be compromised through malicious instructions embedded in seemingly trusted data sources.
The attack exploited several weaknesses, including inadequate context validation, permissive AI model behavior, and a critical Content Security Policy (CSP) bypass.
The vulnerability, with a CVSS score of 9.4, involved a sophisticated indirect prompt injection attack.
Attackers could create a malicious Web-to-Lead submission containing unauthorized commands. The AI agent, when processing this lead, interpreted the malicious instructions as legitimate, resulting in data exfiltration.
The attack vector was an indirect prompt injection , where malicious instructions are embedded in data the AI processes during routine tasks.
A key factor in the attack's success was the discovery of a flaw in Salesforce’s CSP. The domain my-salesforce-cms.com was whitelisted with the opportunity for attackers to acquire it, creating a trusted channel for data exfiltration.
Salesforce has secured the expired domain and implemented stricter security controls, including Trusted URLs Enforcement for both Agentforce and Einstein AI, to prevent similar vulnerabilities.
Exploitation of ForcedLeak could have exposed confidential customer contact information, sales pipeline data, internal communications, and historical interaction records. Organizations using Salesforce Agentforce with the Web-to-Lead feature enabled were particularly at risk.
Salesforce recommends the following actions:
Apply the recommended updates to enforce Trusted URLs for Agentforce and Einstein AI. Audit existing lead data for suspicious submissions containing unusual instructions. Implement strict input validation and sanitize all data from untrusted sources.
Based on reporting by Cyber Security News.
