Salesforce Agentforce was susceptible to a critical indirect prompt injection vulnerability, codenamed ForcedLeak (CVSS 9.4). This flaw allowed attackers to exfiltrate sensitive CRM data by manipulating Web-to-Lead forms, causing AI agents to transmit information to an attacker-controlled domain.
Why This Matters
Publisher reporting describes a security event affecting MCP. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether MCP is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2025-49596
Affected