Opening ForcedLeak — indirect prompt injection in Salesforce Agentforce on Rogue Agent Watch.
Reported · Primary sourcing · AI load-bearing · Critical severity.
Noma Security disclosed "ForcedLeak" (CVSS 9.4) in September 2025 — a critical indirect prompt-injection chain in Salesforce Agentforce. Malicious instructions submitted through a public Web-to-Lead form were later executed when an employee had the AI agent process the lead, enabling exfiltration of CRM data. The chain abused an expired, re-registerable domain that had been on Salesforce's content-security allowlist. Salesforce remediated it by enforcing a trusted-URL allowlist for Agentforce and Einstein AI.
Data: Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, CC BY-SA 4.0.