Accountability is racing autonomy. Zenity showed how a poisoned Web-to-Lead could steer Agentforce into silent CRM data theft via image/DNS and Slack unfurling, plus agent-identity phishing gaps in Slack replies. Salesforce remediated; researchers say the specific chains are closed.

What Zenity found

Zenity Labs disclosed three Salesforce Agentforce weaknesses, collectively called SalesBleed, on 24 September 2026. An attacker could plant an indirect prompt injection in a public Web-to-Lead form. When an employee later asked the agent about leads, the agent could query CRM records and exfiltrate fields through HTML image tags that triggered DNS lookups — or through Slack link unfurling — without the employee clicking anything.

The researchers said the injection lived in data that arrives from outside and is trusted on the way in. Web-to-Lead endpoints are unauthenticated by design. The same default General CRM subagent held permissions for both Leads and Accounts, so the payload did not need to escalate privileges. Salesforce’s Trusted URLs redaction layer was meant to strip untrusted URLs from agent output; Zenity bypassed it by combining gaps in how hostnames and URL endings were recognised.

Slack and identity gaps

For agents published to Slack, Zenity said a raw URL was enough: Slack’s preview crawler would fetch the link and complete the same DNS exfiltration. Related Register coverage described a Slack “Reply to Thread” gap that could let messages go out under the agent’s identity without confirmation or clear attribution.

What was patched

Zenity reported the issues to Salesforce on 1 June 2026. Salesforce confirmed it was working on fixes, and Zenity said the Trusted URLs bypass and related chains were fully confirmed closed by 18–19 August 2026. Salesforce said it had seen no evidence of real-world exploitation of these issues. The researchers were explicit that this specific chain no longer works, while noting the underlying pattern — an agent that reads externally submitted records and also holds CRM tool access — is not unique to one vendor.

Coverage context

Workplace agents that read externally submitted records and hold CRM tool access sit at the same junction as everyday sales and service workflows. The disclosure landed in a cycle already dominated by incident inventories and public inquiry.

Read the full daily brief hub: www.aifusionautomations.com/news/