VulnerabilitiesWeb form plus expired domain let attackers pull data from Agentforce
Noma Security rated the chain 9.4 on the CVSS scale. Salesforce patched it and re-secured a domain that had been left to lapse.
26 Sept 2025
Noma Security chained a prompt injection in a lead-capture form with an expired domain still trusted by Salesforce's content security policy to pull CRM records out of Agentforce. Rated CVSS 9.4.
Occurred 28 July 2025 · Disclosed 25 September 2025 · Record updated 13 September 2026
Customer and lead data in any tenant using Web-to-Lead with Agentforce could be exfiltrated. Salesforce enforced trusted-URL allow-lists and re-secured the domain.
VulnerabilitiesNoma Security rated the chain 9.4 on the CVSS scale. Salesforce patched it and re-secured a domain that had been left to lapse.
26 Sept 2025