
Twice in twelve months, researchers have taken control of Salesforce's AI assistant by typing instructions into a form that anyone on the internet can fill in. Both times the assistant did what the stranger wrote. In the first case it pulled sales leads out of the CRM and sent them to a domain the researchers had bought for five dollars. Salesforce fixed that one in September 2025 and the last of the new batch on September 21, 112 days after it was reported. Nobody has reported either being used against a real company.
The patch notes are not the story. The story is that the same door has worked twice, and the people whose records came out of it never agreed to any of it. They filled in a form on some company's website because they wanted a price or a demo. That company bought Salesforce. Salesforce built an assistant. The assistant reads the box strangers type into, and Salesforce has now twice been unable to stop it acting on what it reads.
In September 2025, Noma Security disclosed ForcedLeak, a prompt-injection chain rated 9.4, which hid its payload in the 42,000 character description field of a Web-to-Lead submission. That is the form sitting behind "contact us" on a large number of B2B websites. The researchers found an expired domain still on Salesforce's list of trusted addresses, bought it for five dollars, and collected the stolen lead data there. Salesforce's answer was to start enforcing that list, so agents could not send anything to an address that was not on it.
Read the sequence back slowly. The platform sells a company a form so strangers can write into its database. Then it sells the company an assistant that reads what the strangers wrote and believes it. Then it sells the company a list of approved addresses so the assistant cannot mail the results to whoever asked. Then somebody buys an address on the approved list for five dollars.
SalesBleed, the name Zenity Labs gave this month's set of three flaws, is not a new category of problem. One got data out while the trusted-address check falsely reported that the content had been blocked. A second exploited the way that same check parsed certain top-level domains and character sequences. Both went around the control Salesforce shipped after ForcedLeak. Salesforce's answer this time was to push the trusted-address check deeper into core components, and to change the default so that Agentforce actions in Slack now ask a user to confirm before sending.
An allowlist assumes you can name the bad destinations in advance. The input here is written by anyone with a browser, and the instruction it carries is not code, it is a sentence.
The third flaw is the one that should worry anyone who has ever filled in a security questionnaire. Zenity used the assistant's Slack integration to send messages through the assistant's own trusted identity, without naming the real sender. Employees got a request from a system already working inside their company rather than from a stranger. Specially built links made it worse, because Slack unfurls links automatically, so CRM data left the building as soon as the message appeared and nobody had to click anything.
We argued last week that the answer to a deepfaked colleague on a video call is to hang up and verify out of band. Same problem, different pipe. The impersonated party here is a system, and it has better standing inside the company than most of its vendors do.
Zenity's own framing is that the risk pattern is not specific to Agentforce. An assistant is exposed when it takes untrusted input from outside, treats what it reads in a record as an instruction, renders links and images back to a person, and holds query access to sensitive data. That is close to the default build of a lead triage agent.
Whether anyone would even notice is a separate question. In LeanData's survey of 157 B2B practitioners, 93% had deployed at least one AI agent, roughly a third could not say how many were acting on their records, and 30% had found actions taken with no audit trail. We wrote earlier this month that AI now reads a CRM written from memory. It also writes to one, and three in ten teams cannot reconstruct what it did. If the company cannot reconstruct it, the person who filled in the form has no chance.
Which is the part worth sitting with. Every form on every website is a promise: type your details in here and we will look after them. That promise now runs through a vendor's ability to control an assistant nobody outside the company can see, and that vendor has been beaten at the same door twice. Salesforce will patch the third one too. Before it does, ask your own vendors a question their AI roadmap does not answer: which agents read records submitted by strangers, and what can those agents query. Any company that cannot answer that today will answer it later in a breach notification, and the notification will carry its name, not Salesforce's.