Web form plus expired domain let attackers pull data from Agentforce
Noma Security rated the chain 9.4 on the CVSS scale. Salesforce patched it and re-secured a domain that had been left to lapse.
By The Agentic Times ·

Salesforce's Agentforce could be manipulated into sending CRM data to an attacker through its Web-to-Lead feature, Noma Security disclosed in September 2025. The company called the vulnerability ForcedLeak and gave it a CVSS score of 9.4.
Web-to-Lead lets a company embed a form on its website that creates lead records in Salesforce. Noma found that the form's description field accepted long text and that an Agentforce agent processing the lead would treat instructions in that text as if they came from an employee. The researchers used the field to tell the agent to query other records and send the results to an external URL.
That second step should have been blocked by Salesforce's content security policy, which limits where agents can send data. Noma discovered that one of the allow-listed domains had expired and was available to register for a few dollars. Once they owned the domain, the exfiltration passed the policy checks.
Salesforce said it had deployed patches to enforce trusted-URL allow-lists for Agentforce and Einstein AI agents, and had re-secured the expired domain. The company said it was not aware of exploitation in the wild.
Noma said the case showed how an agent's blast radius extends to every input field it can read, including public web forms. It also argued that allow-lists need the same lifecycle management as any other security control, since a stale entry can silently become an attacker's asset.
Sources
- noma.securityhttps://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/
