How a lead form becomes an attack vector
Agentforce, Salesforce's AI agent layer for its CRM, is designed to let sales and support staff ask a natural-language assistant to review incoming leads, summarize accounts, and take routine actions without touching the underlying records directly. SalesBleed exploits that convenience by injecting hidden instructions into the free-text fields of a public Web-to-Lead form, the same kind of form countless companies embed on their own marketing sites to capture inbound interest. When an employee later asks Agentforce to review new leads, the agent reads the poisoned entry and follows the embedded instructions as if they came from a trusted internal source.
The exfiltration path is the clever part. The agent encodes sensitive CRM data, including company names and deal sizes, into malformed URLs structured as DNS queries, a channel that Salesforce's Trusted URLs filter was not built to recognize as untrustworthy. Researchers noted this repeats almost exactly the entry point behind ForcedLeak, a separate Agentforce vulnerability disclosed in 2025, which means a control specifically built to stop agents from leaking data to untrusted destinations has now failed to recognize the same destination type twice.
The identity-hijacking flaw is the quieter risk
The third flaw works differently and may be more dangerous in practice. Agentforce's Slack integration includes a Reply action that can post messages without requiring confirmation and without attaching proper attribution to the message's true origin. An attacker who can manipulate the agent's inputs can get it to drop a phishing link into a Slack thread under the bot's own established, trusted identity, the same identity employees have learned to click without a second thought because it is the company's own sanctioned AI assistant.
That is a harder problem to patch away than a filter gap, because it exploits earned trust rather than a technical control. Employees are, correctly, trained to be suspicious of unsolicited links from unknown senders. They are not trained to be suspicious of a link posted by the internal AI tool their own company deployed and told them to rely on, which is exactly the gap this flaw was built to exploit.
Salesforce's response and what it tells us
Salesforce confirmed all three issues were patched by August 19, hardened the Trusted URLs mechanism specifically to catch the DNS-encoding trick, and added proper attribution to Slack messages so a reply generated by an agent is now distinguishable from one a human typed. The company also reported finding no evidence of real-world exploitation before the fixes shipped, which is the best-case outcome for a vulnerability of this type and worth taking at face value absent evidence otherwise.
No CVE numbers were assigned to any of the three flaws, because Agentforce is a managed service rather than software a customer installs and patches on their own timeline. That detail cuts both ways for enterprise buyers: it means Salesforce can push a fix instantly without waiting on customer upgrade cycles, but it also means there is no public CVE a security team can track in its own vulnerability management tooling, which makes this entire class of risk harder to monitor through conventional processes.
Why the same door keeps getting picked
ForcedLeak and SalesBleed share an entry point, not just a vendor, and that repetition is the real finding here. Public-facing lead capture forms are, by design, open to anyone on the internet, which makes them a permanent, unauthenticated input channel directly into whatever downstream system processes their contents, now including an AI agent empowered to take action on what it reads. Patching the specific exfiltration technique each time a researcher finds a new encoding trick is necessary, but it treats a symptom rather than the underlying architectural gap.
That gap is the difference between an agent trusting data because it arrived through an authenticated internal channel and an agent trusting data because it happens to be formatted correctly. Any enterprise running Agentforce, or any comparable agent layered on top of a CRM with public-facing lead capture, should ask its vendor directly how untrusted input from public forms is isolated from the instructions an agent is willing to follow, rather than assuming the most recent patch closed the category for good.
The enterprise takeaway beyond Salesforce
This is not a reason to pull back from Agentforce specifically; Salesforce responded quickly and the fixes appear sound. It is a reason to generalize the lesson across every AI agent an enterprise has connected to a public-facing input channel, whether that is a lead form, a support ticket intake, or a public API endpoint that feeds an internal assistant. Any of those channels can carry the same style of prompt injection that drove both ForcedLeak and SalesBleed.
Security and platform teams evaluating agent deployments should add a specific question to every vendor review from here forward: which public-facing inputs feed this agent, and what happens if one of them is deliberately poisoned. Getting a confident, specific answer to that question is a better predictor of resilience than any benchmark score the vendor can show in a sales deck.



