Skip to main content
VerifiedInjection

ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain

Noma Security showed in September 2025 that hidden instructions placed in a public lead form's description field are executed by Salesforce Agentforce when an employee later asks the agent to process that lead. The data left through a domain on Salesforce's own allowlist that had expired and which the researchers repurchased. Salesforce shipped enforcement of trusted URLs before disclosure.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0011
Kind
Injection
Jurisdiction
United States
Last verified
Added
  • Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
  • The description field on the public lead form was chosen because its large character limit accommodates complex payloads.
  • The agent executed the hidden payload alongside the employee's legitimate request, using the employee's own query authority.
  • Salesforce acknowledged the report three days after it was made and shipped trusted URL enforcement before public disclosure.
  • Salesforce states its underlying services now enforce the trusted URL allowlist so no malicious links are called or generated.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
The lead form accepts anonymous external submissions, and that text became instructions to an internal agent.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
AuthorizationSilent
The agent ran the hidden payload with the employee's CRM query authority attached to it.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
DelegationSilent
No narrowed credential separated summarising one lead from querying other customer records.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
LimitsSilent
The egress allowlist was the intended limit and it existed, but one entry had lapsed at the registrar, so the boundary was only as strong as a domain renewal.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
Human approvalSilent
The employee approved processing a lead, not the outbound data call the payload triggered.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
RevocationStated
Salesforce secured the lapsed domain and enforced trusted URLs on its own services before the research was published.The Hacker News, Salesforce patches critical ForcedLeak bug, secondary source, 25 September 2025.
AccountabilityStated
A named vendor fix, a published coordinated timeline and an on record vendor statement.The Hacker News, Salesforce patches critical ForcedLeak bug, secondary source, 25 September 2025.

Figures

Every number, with who measured it and when

  1. 9.4 CVSS base score

    CVSS severity the researchers assigned

    Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .

  2. 5 US dollars

    Cost of repurchasing the expired allowlisted domain

    Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .

What it changes

For a team deploying an agent

An egress allowlist is only as good as the registrar renewal behind every entry on it. Audit your agent's allowed destinations the way you audit certificates: own every domain on the list, monitor expiry, and remove anything you do not control. Then stop treating a public form as data, because for an agent it is an instruction channel from any stranger with a browser.

Sources

What this record was verified against

  1. Noma Security, ForcedLeak agent risks exposed in Salesforce AgentforcePrimary · 25 September 2025
  2. The Hacker News, Salesforce patches critical ForcedLeak bugSecondary · 25 September 2025
  3. The Register, Salesforce Agentforce ForcedLeak attackSecondary · 26 September 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0011 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), forcedleak, a lead form that turned a crm agent into an exfiltration path through an expired allowlisted domain.
APA
GAGE (Global Academy of Generative-AI Education). (2026). ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead
MLA
"ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead.
Chicago
GAGE (Global Academy of Generative-AI Education). "ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.