ForcedLeak (CVE-2025-32731)
A September 2025 indirect prompt injection vulnerability in Salesforce Agentforce disclosed by Noma Security, scored CVSS 9.4. A field on a public web-to-lead form became an injection vector: Agentforce, processing new leads, would read the payload as instructions and exfiltrate CRM data. ForcedLeak is notable because the attack surface was a *public form*—no compromised employee, no phishing—demonstrating that any customer-facing input field an AI agent consumes is a potential injection vector.
Frequently asked questions
- Do all customer-facing forms need injection-hardening now?
- Any form whose contents will be read by an AI agent downstream, yes. That includes web-to-lead forms, support ticket submissions, contact-us forms, and product review fields. Input sanitization at the form boundary plus least-privilege tool scopes on the agent are the two-layer defense.