Executive Summary
In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch.
This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.
Why This Matters Now
Prompt injection vulnerabilities in widely-used enterprise AI platforms like Salesforce Agentforce expose sensitive organizational data to novel attack paths. With increasing AI adoption in cloud applications and pressure to meet compliance mandates, urgent attention is required to proactively defend against abuse of generative AI integrations before attackers widely exploit these weaknesses.
Attack Path Analysis
Attackers exploited an indirect prompt injection vulnerability (ForcedLeak) in Salesforce Agentforce to trigger unauthorized AI behaviors and gain access to sensitive CRM data. Having compromised the AI agent, they leveraged weaknesses in privilege boundaries to access data meant for higher-privileged roles. The attackers moved laterally within the cloud environment, exploring multiple tenant or data boundaries. They established covert command and control using legitimate application or SaaS communications. Sensitive CRM data was then exfiltrated by instructing the AI to leak contents via outbound channels. The impact resulted in unauthorized disclosure of confidential business information, eroding trust and potentially leading to regulatory consequences.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited the ForcedLeak prompt injection vulnerability in Agentforce to manipulate AI agents into executing unauthorized instructions.
Related CVEs
CVE-2025-64320
CVSS 9.4Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.
Affected Products:
Salesforce Agentforce Vibes Extension – < 3.2.0
Exploit Status:
no public exploitCVE-2025-64322
CVSS 8.8Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.
Affected Products:
Salesforce Agentforce Vibes Extension – < 3.3.0
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Command and Scripting Interpreter: JavaScript
Data Manipulation: Stored Data Manipulation
Browser Extensions
User Execution: Malicious File
Phishing: Spearphishing Attachment
Automated Exfiltration
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Software Applications
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Continuous Application Security Testing
Control ID: Pillar: Applications, Capability: Application Security
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical ForcedLeak vulnerability in Salesforce Agentforce exposes CRM data through AI prompt injection, requiring immediate zero trust segmentation and egress security controls.
Financial Services
High-risk CRM data exfiltration via AI prompt injection threatens sensitive financial customer data, demanding enhanced cloud application security and multicloud visibility controls.
Health Care / Life Sciences
HIPAA-regulated patient data in Salesforce CRM vulnerable to ForcedLeak exploit, necessitating encrypted traffic protection and anomaly detection for compliance maintenance.
Marketing/Advertising/Sales
Direct exposure to Salesforce CRM vulnerability enables customer data theft through AI agent manipulation, requiring immediate cloud firewall and threat detection implementation.
Sources
- Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injectionhttps://thehackernews.com/2025/09/salesforce-patches-critical-forcedleak.htmlVerified
- Salesforce Security Advisory: Agentforce Vibes Extension Vulnerabilitieshttps://help.salesforce.com/s/articleView?id=005228032&type=1Verified
- NVD - CVE-2025-64320https://nvd.nist.gov/vuln/detail/CVE-2025-64320Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic security, policy-driven egress controls, and distributed visibility provided by CNSF capabilities could have detected, contained, or outright blocked malicious prompt injection exploitation, lateral expansion, and sensitive data leaks at multiple cloud kill chain stages.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline security fabric would have detected and policy-flagged suspicious AI-driven behaviors.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation would have limited agent access scope to only authorized datasets.
Control: East-West Traffic Security
Mitigation: Monitored and restricted internal traffic, stopping unauthorized east-west traversal.
Control: Cloud Firewall (ACF) with Inline IPS
Mitigation: Inline detection and policy controls would flag/detect C2-like activity in outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Policy-driven egress filtering halts exfiltration attempts in real time.
Centralized visibility enables rapid detection and incident response to limit overall impact.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive customer data from the CRM system due to unauthorized code execution.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy east-west traffic segmentation and microsegmentation to strictly isolate AI agents and sensitive data stores.
- • Enforce granular, identity-based least privilege policies to prevent excessive access by AI workflows and applications.
- • Implement inline anomaly detection and distributed inspection for early detection of suspicious prompt injection and SaaS misuse behaviors.
- • Apply policy-driven egress controls, including FQDN and application-based filtering, to block unauthorized data egress channels.
- • Enhance centralized, cloud-native visibility and incident response orchestration to ensure rapid detection, investigation, and compliance actions.



