Would Ethosure have caught this? — Salesforce Agentforce’s ForcedLeak indirect prompt injection
Noma Labs’ Sasi Levi demonstrated a CVSS 9.4 chain in Salesforce Agentforce: a malicious Web-to-Lead submission stored 42,000 characters of injected instructions in the CRM, then exfiltrated data through a rendered image on an expired trusted domain. Salesforce patched via Trusted URLs Enforcement on September 8, 2025. Tenant-owned CRM records were the prompt-injection vector. The fix is policy on the agent, not just on the domain allowlist.







