This research outlines how Noma Labs discovered ForcedLeak, a critical severity (CVSS 9.4) vulnerability chain in Salesforce Agentforce that could enable external attackers to exfiltrate sensitive CRM data through an indirect prompt injection attack. [...] The LLM, operating as a straightforward execution engine, lacked the ability to distinguish between legitimate data loaded into its context and malicious instructions that should only be executed from trusted sources, resulting in critical sensitive data leakage.
Curated from noma.security · 25 September 2025 →
Web-to-Lead is the Salesforce form on a company's own website that turns an enquiry into a CRM record. Anyone on the internet can fill one in. Noma Labs put instructions in the Description field, and when an employee later asked Agentforce about their leads the agent read them and obeyed. Getting the data out needed one more thing, because Salesforce only allows the agent to reach allowlisted domains: Noma found a domain on that list that had expired, and bought it for five dollars. Reported on 28 July 2025; Salesforce re-secured the domain and shipped Trusted URL enforcement on 8 September. The expired allowlist entry is the part worth acting on, because every company with an agent has a list like that and nobody is watching it for renewals.