Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

ForcedLeak: Salesforce Agentforce leaks CRM data through a Web-to-Lead form

Noma Security chained a prompt injection in a lead-capture form with an expired domain still trusted by Salesforce's content security policy to pull CRM records out of Agentforce. Rated CVSS 9.4.

Occurred 28 July 2025 · Disclosed 25 September 2025 · Record updated 13 September 2026

Impact

Customer and lead data in any tenant using Web-to-Lead with Agentforce could be exfiltrated. Salesforce enforced trusted-URL allow-lists and re-secured the domain.

Our coverage

Sources

  1. noma.securityhttps://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/