Researchers studying cybersecurity have found a serious vulnerability in Salesforce Agentforce, a platform for creating artificial intelligence (AI) agents, that may enable hackers to use an indirect prompt injection to steal confidential information from the CRM tool.
On July 28, 2025, Noma Security identified and reported the vulnerability, which they have nicknamed ForcedLeak (CVSS score: 9.4). It affects any company that uses Salesforce Agentforce and has Web-to-Lead enabled.
This flaw illustrates how, in contrast to conventional prompt-response systems, AI agents offer a radically different and wider attack surface. According to a source provided to The Hacker News, Sasi Levi is the lead for security research at Noma.
Indirect prompt injection, which happens when malicious instructions are inserted into external data sources that the service accesses, is one of the most serious threats that generative artificial intelligence (GenAI) systems face today read more about Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
