Would Ethosure have caught this? Salesforce Agentforce’s ForcedLeak indirect prompt injection

Noma Labs’ Sasi Levi demonstrated a CVSS 9.4 chain in Salesforce Agentforce: a malicious Web-to-Lead submission stored 42,000 characters of injected instructions in the CRM, then exfiltrated data through a rendered image on an expired trusted domain. Salesforce patched via Trusted URLs Enforcement on September 8, 2025. Tenant-owned CRM records were the prompt-injection vector. The fix is policy on the agent, not just on the domain allowlist.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.