Security researchers disclosed a critical indirect prompt injection vulnerability, dubbed ForcedLeak, in Salesforce’s Agentforce AI agent platform. Attackers could embed malicious instructions in the description field of a public-facing Web-to-Lead form, and when an internal employee asked the agent to review the lead, it would execute the hidden instructions and exfiltrate CRM lead records to an attacker-controlled domain. Salesforce patched the flaw, which was rated 9.4 on the CVSS scale, and no confirmed real-world exploitation against customers was reported.