ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain
Noma Security showed in September 2025 that hidden instructions placed in a public lead form's description field are executed by Salesforce Agentforce when an employee later asks the agent to process that lead. The data left through a domain on Salesforce's own allowlist that had expired and which the researchers repurchased. Salesforce shipped enforcement of trusted URLs before disclosure.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0011
- Kind
- Injection
- Jurisdiction
- United States
- Last verified
- Added
- Noma Security states that an allowlisted domain had expired and become available for purchase, and that the researchers bought it.
- The description field on the public lead form was chosen because its large character limit accommodates complex payloads.
- The agent executed the hidden payload alongside the employee's legitimate request, using the employee's own query authority.
- Salesforce acknowledged the report three days after it was made and shipped trusted URL enforcement before public disclosure.
- Salesforce states its underlying services now enforce the trusted URL allowlist so no malicious links are called or generated.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Delegation, Limits, Human approval, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- The lead form accepts anonymous external submissions, and that text became instructions to an internal agent.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
- AuthorizationSilent
- The agent ran the hidden payload with the employee's CRM query authority attached to it.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
- DelegationSilent
- No narrowed credential separated summarising one lead from querying other customer records.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
- LimitsSilent
- The egress allowlist was the intended limit and it existed, but one entry had lapsed at the registrar, so the boundary was only as strong as a domain renewal.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
- Human approvalSilent
- The employee approved processing a lead, not the outbound data call the payload triggered.Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, 25 September 2025.
- RevocationStated
- Salesforce secured the lapsed domain and enforced trusted URLs on its own services before the research was published.The Hacker News, Salesforce patches critical ForcedLeak bug, secondary source, 25 September 2025.
- AccountabilityStated
- A named vendor fix, a published coordinated timeline and an on record vendor statement.The Hacker News, Salesforce patches critical ForcedLeak bug, secondary source, 25 September 2025.
Figures
Every number, with who measured it and when
- 9.4 CVSS base score
CVSS severity the researchers assigned
Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .
- 5 US dollars
Cost of repurchasing the expired allowlisted domain
Noma Security, ForcedLeak agent risks exposed in Salesforce Agentforce, primary source, as of .
What it changes
For a team deploying an agent
An egress allowlist is only as good as the registrar renewal behind every entry on it. Audit your agent's allowed destinations the way you audit certificates: own every domain on the list, monitor expiry, and remove anything you do not control. Then stop treating a public form as data, because for an agent it is an instruction channel from any stranger with a browser.
Sources
What this record was verified against
- Noma Security, ForcedLeak agent risks exposed in Salesforce AgentforcePrimary · 25 September 2025
- The Hacker News, Salesforce patches critical ForcedLeak bugSecondary · 25 September 2025
- The Register, Salesforce Agentforce ForcedLeak attackSecondary · 26 September 2025
Related
Records that sit beside this one
ShareLeak, where a public form field overrode an enterprise agent's instructions and mailed out customer records
United States · verified 15 September 2026
The research states that the compromised agent accesses connected lists and sends sensitive customer data to an attacker controlled email address.
A support ticket steered a developer's assistant into reading a database through the Supabase MCP server
United States · verified 15 September 2026
General Analysis states that the editor assistant ingests untrusted customer text while holding service role privileges.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0011 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), forcedleak, a lead form that turned a crm agent into an exfiltration path through an expired allowlisted domain.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead
- MLA
- "ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "ForcedLeak, a lead form that turned a CRM agent into an exfiltration path through an expired allowlisted domain." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0011-forcedleak-salesforce-agentforce-web-to-lead
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.