Close Menu
TechurzTechurz
    What's Hot

    Meet Wrinkles, an AI app that uncovers the hidden stories of the places around you

    August 4, 2026

    Take an extra $100 off your TechCrunch Disrupt 2026 pass: This week only!

    August 4, 2026

    Bending Spoons to buy Airtable for $1.28B

    August 4, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Meet Wrinkles, an AI app that uncovers the hidden stories of the places around you
    • Take an extra $100 off your TechCrunch Disrupt 2026 pass: This week only!
    • Bending Spoons to buy Airtable for $1.28B
    • Base Power raises another $1B to save the grid using backyard batteries
    • Design Arena creators raise $7.9 million to bring taste to AI models
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
    Cyber Reality

    Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection

    TechurzBy TechurzSeptember 25, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Sep 25, 2025Ravie LakshmananVulnerability / AI Security

    Cybersecurity researchers have disclosed a critical flaw impacting Salesforce Agentforce, a platform for building artificial intelligence (AI) agents, that could allow attackers to potentially exfiltrate sensitive data from its customer relationship management (CRM) tool by means of an indirect prompt injection.

    The vulnerability has been codenamed ForcedLeak (CVSS score: 9.4) by Noma Security, which discovered and reported the problem on July 28, 2025. It impacts any organization using Salesforce Agentforce with the Web-to-Lead functionality enabled.

    “This vulnerability demonstrates how AI agents present a fundamentally different and expanded attack surface compared to traditional prompt-response systems,” Sasi Levi, security research lead at Noma, said in a report shared with The Hacker News.

    One of the most severe threats facing generative artificial intelligence (GenAI) systems today is indirect prompt injection, which occurs when malicious instructions are inserted into external data sources accessed by the service, effectively causing it to generate otherwise prohibited content or take unintended actions.

    The attack path demonstrated by Noma is deceptively simple in that it coaxes the Description field in Web-to-Lead form to run malicious instructions by means of a prompt injection, allowing a threat actor to leak sensitive data and exfiltrate it to a Salesforce-related allowlisted domain that had expired and become available for purchase for as little as $5.

    This takes place over five steps –

    • Attacker submits Web-to-Lead form with a malicious Description
    • Internal employee processes lead using a standard AI query to process incoming leads
    • Agentforce executes both legitimate and hidden instructions
    • System queries CRM for sensitive lead information
    • Transmit the data to the now attacker-controlled domain in the form of a PNG image

    “By exploiting weaknesses in context validation, overly permissive AI model behavior, and a Content Security Policy (CSP) bypass, attackers can create malicious Web-to-Lead submissions that execute unauthorized commands when processed by Agentforce,” Noma said.

    “The LLM, operating as a straightforward execution engine, lacked the ability to distinguish between legitimate data loaded into its context and malicious instructions that should only be executed from trusted sources, resulting in critical sensitive data leakage.”

    Salesforce has since re-secured the expired domain, rolled out patches that prevent output in Agentforce and Einstein AI agents from being sent to untrusted URLs by enforcing a URL allowlist mechanism.

    “Our underlying services powering Agentforce will enforce the Trusted URL allowlist to ensure no malicious links are called or generated through potential prompt injection,” the company said in an alert issued earlier this month. “This provides a crucial defense-in-depth control against sensitive data escaping customer systems via external requests after a successful prompt injection.”

    Besides applying Salesforce’s recommended actions to enforce Trusted URLs, users are recommended to audit existing lead data for suspicious submissions containing unusual instructions, implement strict input validation to detect possible prompt injection, and sanitize data from untrusted sources.

    “The ForcedLeak vulnerability highlights the importance of proactive AI security and governance,” Levi said. “It serves as a strong reminder that even a low-cost discovery can prevent millions in potential breach damages.”

    bug Critical CRM data exposing ForcedLeak injection patches prompt Salesforce
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleLess than 48 hours to grab your Disrupt 2025 ticket savings
    Next Article Find out if AI is really helping us find ‘the one’ at Disrupt 2025
    Techurz
    • Website

    Related Posts

    Opinion

    Why this CEO thinks video games make better training data than the internet

    July 8, 2026
    Opinion

    Omen AI’s plan to optimize data centers is all wet

    June 29, 2026
    Opinion

    AI was supposed to kill engineering jobs, but new data suggests they’re the most resilient

    June 24, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.