What happened
An customer-facing CRM agent accesses an expired trusted domain, ingests malicious instructions, and executes tools to package and exfiltrate internal customer directories.
2025-09-12
HighPrimaryAnalysis of the ForcedLeak vulnerability where indirect prompt injection in Salesforce Agentforce exfiltrated CRM data via an expired trusted domain.
What happened
An customer-facing CRM agent accesses an expired trusted domain, ingests malicious instructions, and executes tools to package and exfiltrate internal customer directories.
Why it matters
Unauthorized exposure and exfiltration of corporate Salesforce CRM databases, containing sensitive customer accounts and pipeline values.
Missing authorization check
All bulk database reads and inter-system data transmissions must require an out-of-band human-signed cryptographic receipt.
Would PP block it?
Even if an attacker hijacks the Agentforce LLM using indirect prompt injection, any subsequent tool call attempting to query multiple CRM rows or post data to external servers is routed through PP's Tool-Call Gate. Since the injected prompt cannot generate a valid operator cryptographic signature, the tool call fails-close, blocking the leak.
Incident analysis
2025-09-12
Noma discloses ForcedLeak vulnerability affecting Salesforce Agentforce deployments.
2025-09-15
Salesforce releases patches restricting Agentforce domain-trust assumptions and adding prompt filtering.
Authorization boundary
This incident is categorized as Governance bypass. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
PP's Tool-Call Gate blocks any bulk CRM read or external exfiltration attempts that do not present a verified operator cryptographic signature.
Related incidents and controls
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.