• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Sq Magazine LogoSQ Magazine

Smarter Insights for a Fast-Moving Digital World

  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Sq Magazine Logo
  • Latest News
  • Statistics
  • About
  • Contact
Subscribe
Home » Cybersecurity

Critical Prompt Injection Bug in Salesforce AI Shows Emerging AI Security Threats

Published on: September 26, 2025
Sofia Ramirez
Written By
Sofia Ramirez
Sofia Ramirez
Senior Tech Writer • 451 Articles
Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps reader...
LATEST POSTS:
Bajaj Auto Confirms Ransomware Attack on Key Systems
The Numbers Behind the Next Big Tech Startup
Adobe Creative Cloud Statistics 2026: Subscribers, Revenue and Market Share
Prompt Injection Bug In Salesforce Ai
As Featured In
The New York Times LogoForbes LogoWired LogoDeloitte LogoResearch.com Logo
Share on LinkedIn ChatGPT Perplexity Share on X Share on Facebook

A newly discovered vulnerability in Salesforce’s Agentforce platform shows how AI driven tools can open novel attack paths for criminal actors. The bug, named ForcedLeak, leveraged an indirect prompt injection exploit to siphon sensitive CRM data, highlighting the evolving dangers of integrating autonomous AI agents into enterprise workflows.

Quick Summary – TLDR:

  • A CVSS 9.4 critical flaw in Salesforce Agentforce called ForcedLeak lets attackers hide malicious instructions in Web to Lead forms
  • When employees later interact with those leads via the AI agent, the hidden instructions are executed, causing data to leak
  • Attackers exploited a now expired but whitelisted domain to receive the exfiltrated data
  • Salesforce has issued patches, revoked the expired domain, and enforced Trusted URL rules

What Happened?

Security researchers at Noma Labs discovered ForcedLeak on July 28, 2025, and disclosed it to Salesforce. The flaw affects organizations using Agentforce with the Web to Lead feature enabled. In short, attackers insert hidden instructions inside the Description field of a Web to Lead form. These instructions look benign. Later, when an internal user asks Agentforce to process that lead, the AI agent runs both the legitimate query and the hidden payload. That payload then queries the CRM for sensitive data and transmits it to a domain the attacker now controls.

ForcedLeak: AI Agent risks exposed in Salesforce AgentForce – https://t.co/JMsazzE6PD By @sasi2103

This research outlines how @NomaSecurity discovered ForcedLeak, a critical severity (CVSS 9.4) vulnerability chain in Salesforce Agentforce that could enable external attackers to…

— AISecHub (@AISecHub) September 25, 2025

The pivotal factor was that Salesforce had left a domain on its whitelist for Content Security Policy (CSP) that had expired. The attacker re registered that domain cheaply (for around $5) and used it as a trusted destination. Because the domain was still allowed in the CSP, exfiltration appeared legitimate from the system’s perspective.

The attack chain included injection via form, delayed execution by the AI agent, CRM query, and data egress over a whitelisted external channel. All of this happened without raising immediate alarms.

Why This Is Worse Than a Traditional Bug?

Most vulnerabilities are exploited almost immediately and rely on direct code flaws. However, ForcedLeak succeeds because of how AI agents operate. Agentforce is not a simple chatbot. It reasons, plans, and executes multi step tasks using internal memory, tools, and connected systems. Traditional security controls often assume AI systems only act on explicit user prompts. ForcedLeak shows that data already present in the system can carry hidden commands.

The vulnerability exploited three key lapses:

  1. Context validation failure: The AI could not reliably distinguish between benign user data and hidden commands.
  2. Overly permissive model behavior: Agentforce accepted and acted on injected instructions.
  3. CSP bypass via expired whitelist: The domain allowed the attacker to exfiltrate data unnoticed.

Because the exploit is delayed (the malicious payload only triggers upon later interactions), it can remain hidden until an employee interacts with the tainted lead. This makes detection more difficult.

What Salesforce Did and What Users Must Do?

Once notified, Salesforce moved quickly. The expired whitelisted domain was secured or removed. Patches were released that enforce a Trusted URL allowlist for both Agentforce and Einstein AI, preventing output to untrusted domains. Salesforce also stated that its underlying services would enforce the Trusted URL control to block malicious links or domains from being generated or used.

But organizations using Agentforce must also act now. Key steps include:

  1. Apply the security patch and ensure Trusted URLs enforcement is active.
  2. Audit existing lead data for anomalous submissions such as extremely long description fields, embedded instructions or code, image tags, or suspicious URL references.
  3. Implement input validation and sanitization on Web to Lead forms to detect prompt style payloads.
  4. Sanitize all data from external sources before including it in any AI prompt or agent context.
  5. Monitor model behavior and output for signs of external calls like image tags pointing to unusual domains.
Newsletter
Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Broader Implications for AI Security

ForcedLeak is not merely a bug. It signals a shift in what security means for AI driven systems. It shows that:

  • AI agents expand the attack surface beyond traditional modules and runtimes to include prompt injection, memory, tool calls, and chained workflows.
  • Security teams must rethink threat modeling. It is no longer enough to secure databases, APIs, and frontend code. You must secure how AI models are fed data, how they interpret it, and where they are allowed to send outputs.
  • Prompt hygiene, context boundaries, memory governance, output filtering, and domain allowlisting are now core components of AI security posture.
  • Even low cost attackers (for example, someone paying $5 to register a domain) can exploit seemingly minor oversights.
  • As more enterprises adopt AI agents, these kinds of indirect and delayed exploits will likely become more common.

SQ Magazine’s Takeaway

I believe ForcedLeak is a wakeup call. We are entering an era where AI agents are not just helpful assistants but potential security liabilities. The very power that makes Agentforce useful gives attackers new ways in.

From now on, defending AI systems means thinking differently. It is not enough to patch code or lock down servers. We must protect the interfaces between data and agent logic. We must treat every piece of content that enters or exits an AI system as a potential vector of attack.

For organizations using AI agents, prevention must go deep. That means strict input sanitation, minimal trust in external domains, constant auditing, and a culture of suspicious prompt hygiene. In other words, security cannot be an afterthought. It must be built into every step of AI integration.

SQ Magazine follows strict Publishing Principles and a documented Fact-Check Policy to ensure accuracy, transparency, and editorial independence across all content.

Add SQ Magazine as a Preferred Source on Google for updates! Follow on Google News
Share ChatGPT Perplexity
Sofia Ramirez

Sofia Ramirez

Senior Tech Writer


Sofia Ramirez is a technology and cybersecurity writer at SQ Magazine. With a keen eye on emerging threats and innovations, she helps readers stay informed and secure in today’s fast-changing tech landscape. Passionate about making cybersecurity accessible, Sofia blends research-driven analysis with straightforward explanations; so whether you’re a tech professional or a curious reader, her work ensures you’re always one step ahead in the digital world.

Related Posts

OpenAI Fixes Major ChatGPT Data Leak and Codex Security Flaws
Cybersecurity

OpenAI Fixes Major ChatGPT Data Leak and Codex Security Flaws

Cursor AI Flaw Lets Hackers Steal API Keys and Run Code Silently
Cybersecurity

Cursor AI Flaw Lets Hackers Steal API Keys and Run Code Silently

40,000+ OpenClaw AI Bots Exposed by Misconfigurations
Cybersecurity

40,000+ OpenClaw AI Bots Exposed by Misconfigurations

Disclaimer: The content published on SQ Magazine is for informational and educational purposes only. Please verify details independently before making any important decisions based on our content.

Reader Interactions

Leave a Comment Cancel reply

Primary Sidebar

Connect With Us

facebook x linkedin google-news telegram pinterest whatsapp email
google-preferred-source-badge Add as a preferred source on Google

You Should Also Read

Critical Argument Injection Flaw Lets Hackers Hijack AI Agents
Prompt Injection Statistics 2026: Hidden Risks Now
GitHub Copilot’s Prompt Injection Flaw Sparks Security Concerns

Table of Contents

  • Quick Summary – TLDR:
  • What Happened?
  • Why This Is Worse Than a Traditional Bug?
  • What Salesforce Did and What Users Must Do?
  • Broader Implications for AI Security
  • SQ Magazine’s Takeaway
Connect on Telegram

Footer

SQ Magazine Logo

Smarter Insights for a Fast-Moving Digital World

Connect With Us

Follow Us on Google News

Editorial & Trust

  • About
  • Publishing Principles
  • Fact-Check Policy
  • Corrections Policy
  • Ethics Policy
  • Disclaimer

Worth Checking

  • Social Media Attention Span Stats
  • Gen Z Social Media Statistics
  • TikTok vs. Instagram Statistics
  • LLM Hallucination Statistics
  • Spotify User Statistics
  • Apple Customer Loyalty Statistics
Contact Us
13570 Grove Dr #189,
Maple Grove, MN 55311,
United States
10 a.m. – 6 p.m. | Every day

Copyright © 2022–2026 SQ Magazine. All Rights Reserved. Powered by the Neural Stack.

  • Privacy Policy
  • Terms
Company
  • About Us
  • Our Team
  • Our Mission
  • Core Values
Discover
  • Brand Assets
    Brand Assets
  • Stats Methodology
    Stats Research Process
  • Glossary
    Glossary
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Google Workspace Statistics 2026: Users, Market Share and AI
Google Workspace Statistics 2026: Users, Market Share and AI
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
YouTube vs TikTok Statistics 2026: Users, Revenue, Creator Economy
Internet Outage Statistics 2026: Frequency, Cost and Causes
Internet Outage Statistics 2026: Frequency, Cost and Causes
Upwork Statistics 2026: Revenue, GSV, AI Work
Upwork Statistics 2026: Revenue, GSV, AI Work
Instagram Reels Statistics 2026: Plays and Engagement
Instagram Reels Statistics 2026: Plays and Engagement
Gig Economy Statistics 2026: Workforce & Earnings
Gig Economy Statistics 2026: Workforce & Earnings
Gaming
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Online Gambling Regulations Statistics 2026: Global Compliance and Enforcement Data
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Fantasy Sports Statistics 2026: Users, Revenue & Trends
Apex Legends Statistics 2026: Players, Revenue, and Esports
Apex Legends Statistics 2026: Players, Revenue, and Esports
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Fortnite Statistics 2026: Players, Revenue, Esports, and Engagement
Gamers Statistics 2026: Players, Habits & Global Data
Gamers Statistics 2026: Players, Habits & Global Data
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Minecraft Statistics 2026: 300 Million Copies Sold & 212M Monthly Players
Technology
Adobe Creative Cloud Statistics 2026: Subscribers, Revenue and Market Share
Adobe Creative Cloud Statistics 2026: Subscribers, Revenue and Market Share
Adobe Statistics 2026: Revenue, ARR, and Workforce Data
Adobe Statistics 2026: Revenue, ARR, and Workforce Data
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Employee Productivity Statistics 2026: Engagement, Costs & Trends
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
Software Engineer Layoff Statistics 2026: Companies, Roles, AI Impact
iPhone Ecosystem Statistics 2026: Big Market Trends
iPhone Ecosystem Statistics 2026: Big Market Trends
Average Screen Time by Age Statistics 2026: Latest Insights
Average Screen Time by Age Statistics 2026: Latest Insights
Artificial Intelligence
Copilot Statistics 2026: Users, Adoption, Revenue and Market Share
Copilot Statistics 2026: Users, Adoption, Revenue and Market Share
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Image Generation Statistics 2026: Market Size, Adoption & Risks
AI Influencer Marketing Statistics: Market Size and Engagement
AI Influencer Marketing Statistics: Market Size and Engagement
AI Market Statistics 2026: Size, Growth & Investment
AI Market Statistics 2026: Size, Growth & Investment
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Meta AI Statistics 2026: Users, Capex, and Adoption Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Predictive AI Statistics 2026: Market Size, Adoption & Accuracy Data
Cybersecurity
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Password Statistics 2026: Credential Theft, MFA, and the Passkey Tipping Point
Identity Theft Statistics 2026: Key Fraud Data and Trends
Identity Theft Statistics 2026: Key Fraud Data and Trends
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
CVE Statistics 2026: Severity Distribution and Top Affected Vendors
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
Dark Web AI Tool Marketplace Statistics 2026: Explosive Market Growth
API Security Breach Statistics 2026: Hidden Threats
API Security Breach Statistics 2026: Hidden Threats
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
AI Voice Cloning Fraud Statistics 2026: Alarming Trends You Must Know Now
Categories
  • Internet
  • Gaming
  • Technology
  • Artificial Intelligence
  • Cybersecurity
Internet
Meta Hands WhatsApp Reins to CRED Founder Kunal Shah
Meta Hands WhatsApp Reins to CRED Founder Kunal Shah
Major X Outage Disrupts Users Worldwide, Service Restored
Major X Outage Disrupts Users Worldwide, Service Restored
Meta Adds 13+ Content Settings and AI Age Checks for Teens
Meta Adds 13+ Content Settings and AI Age Checks for Teens
Telegram Restricted in India as NEET Fraud Crackdown Grows
Telegram Restricted in India as NEET Fraud Crackdown Grows
UK Unveils Under 16 Social Media Ban With Tough New Rules
UK Unveils Under 16 Social Media Ban With Tough New Rules
Facebook and Instagram Hit by Major Global Outage
Facebook and Instagram Hit by Major Global Outage
Gaming
GTA 6 Pre-Orders Start June 25, New Cover Art Unveiled
GTA 6 Pre-Orders Start June 25, New Cover Art Unveiled
Epic Games Teases Unreal Engine 6 for Rocket League
Epic Games Teases Unreal Engine 6 for Rocket League
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Stardew Valley Switch 2 Edition Arrives with Online Co-op
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
Hogwarts Legacy Crosses 40M Sales, Beating Industry Giants
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
PUBG: Black Budget Launches Closed Alpha Test With a Bold PvPvE Twist
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Counter-Strike 2’s $5.9 Billion Skin Economy Just Got Shattered
Technology
Windows Recycle Bin Bug Confirmed After June Security Update
Windows Recycle Bin Bug Confirmed After June Security Update
Apple Urgently Fixes Beats Studio Buds Bug That Enabled Spying
Apple Urgently Fixes Beats Studio Buds Bug That Enabled Spying
Android 17 Is Here With Powerful AI Features and Security Boosts
Android 17 Is Here With Powerful AI Features and Security Boosts
Telegram Returns to Wear OS With Smartwatch App Upgrade
Telegram Returns to Wear OS With Smartwatch App Upgrade
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple Announces macOS 27 Golden Gate at WWDC 2026
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Apple iPadOS 27 Introduces New Siri App and Productivity Tools
Artificial Intelligence
Gemini 3.5 Flash Gets Powerful Computer Use Features
Gemini 3.5 Flash Gets Powerful Computer Use Features
OpenAI Unveils Powerful Jalapeño AI Chip With Broadcom
OpenAI Unveils Powerful Jalapeño AI Chip With Broadcom
Anthropic Unveils Claude Tag, a Powerful AI Teammate for Slack
Anthropic Unveils Claude Tag, a Powerful AI Teammate for Slack
OpenAI Expands Daybreak With Powerful Cybersecurity AI
OpenAI Expands Daybreak With Powerful Cybersecurity AI
ChatGPT Gets Targeted Ads in Japan as OpenAI Expands
ChatGPT Gets Targeted Ads in Japan as OpenAI Expands
JPMorgan Restricts Anthropic AI Use for Hong Kong Staff
JPMorgan Restricts Anthropic AI Use for Hong Kong Staff
Cybersecurity
Bajaj Auto Confirms Ransomware Attack on Key Systems
Bajaj Auto Confirms Ransomware Attack on Key Systems
LastPass Warns of Data Exposure in Klue Supply Chain Hack
LastPass Warns of Data Exposure in Klue Supply Chain Hack
Meta Stops Employee Tracking Program Over Security Concerns
Meta Stops Employee Tracking Program Over Security Concerns
Tata Electronics Hit by Cyber Breach Linked to Apple Files
Tata Electronics Hit by Cyber Breach Linked to Apple Files
QNAP Patches 14 Dangerous Flaws Affecting NAS Systems
QNAP Patches 14 Dangerous Flaws Affecting NAS Systems
Massive WhatsApp Malware Campaign Hits Users Worldwide
Massive WhatsApp Malware Campaign Hits Users Worldwide
Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.

Newsletter

Subscribe To Our Newsletter!

Be the first to get exclusive offers and the latest news.