DEV Community

Cover image for Salesbleed Isn't a Salesforce Bug. It's What Happens When Agents Trust Their Inputs
Cor E
Cor E

Posted on

Salesbleed Isn't a Salesforce Bug. It's What Happens When Agents Trust Their Inputs

Salesbleed Isn't a Salesforce Bug. It's What Happens When Agents Trust Their Inputs

Here's the part that should bother you: this exploit didn't need a zero-day, a leaked credential, or a misconfigured bucket. It just needed an AI agent doing exactly what it was designed to do, and some text on a web page that the agent wasn't supposed to trust but did anyway.

Context

Prompt injection isn't news. We've been talking about it since the early days of LLM tool use, usually in the context of "what if a chatbot reads a malicious webpage." What's new here is the blast radius. Salesbleed shows the pattern jumping from a single-app annoyance to a cross-application attack chain: agentic Salesforce ingests untrusted web content, hidden instructions ride along, and the agent dutifully relays them into Slack. Now you've got a phishing message that shows up in an internal channel, from a source your team already trusts, carrying an implicit stamp of legitimacy that no external email ever could.

This is the natural next step of giving agents write access to more systems. We spent years hardening the perimeter around inputs humans see directly. Nobody spent nearly as much time hardening the perimeter around inputs an agent sees on your behalf, then acts on with your credentials and your trust graph.

Hype Check

I'd push back a little on calling this a "Salesforce exploit." That framing lets every other vendor with an agentic product off the hook, and there are a lot of them shipping the same architecture right now: agent reads untrusted content, agent has write access somewhere sensitive, nothing in between validates that the content didn't just tell the agent to do something else. Swap in any CRM, any support tool, any agent with Slack or Teams integration, and you get the same failure mode with different branding.

What's understated is the trust transfer problem. The actual danger isn't that the agent got fooled. It's that the output of being fooled lands in a channel where humans have already lowered their guard. We trained people for a decade to be suspicious of external email and links. We have not trained anyone to be suspicious of a message that "came from" an internal automation account in Slack. That's the whole exploit, really. It's a trust-laundering machine.

And to be fair to the researchers: zero HN engagement on this doesn't mean it's not a big deal, it usually means people haven't connected agentic AI security to the stuff they already care about yet. Give it six months.

Implications

For appsec teams, this is a reminder that "agentic AI" adds a new class of untrusted input you don't get to skip. Every piece of content an agent reads while performing an action needs to be treated the way you'd treat user input in a web form ten years ago, except now the attacker doesn't need the user to click anything. The agent clicks for them.

For platform teams building or integrating these agents: least privilege isn't optional anymore, it's the only mitigation that actually works right now. If an agent can read arbitrary web content and also has write access to an internal comms tool, you've built a bridge between your least trusted input and your most trusted output. That bridge needs a checkpoint, whether that's content sanitization, human approval gates on cross-system actions, or just not letting agents post to Slack unsupervised in the first place.

For everyone else: the "it came from an internal tool, must be legit" heuristic is dead. It was already shaky. Now it's actively being weaponized.

Open Question

We spent a decade teaching people to distrust unexpected links and unfamiliar senders. What does security awareness training even look like when the phishing message is technically accurate, internally sourced, and delivered by a system your company built on purpose?

— Cor, Skyblue Soft

Sources


AI-assisted draft or imaging, human-curated, reviewed and edited.

Top comments (1)

Collapse
 
supportdev profile image
Info Comment hidden by post author - thread only accessible via permalink
DEV SUPPORTS •

Dеar Usеr,
Duе tо an increasе in bоt activіty on the рlаtform, we requirе verifу оf your account.
Pleasе log in via the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеаdlіne - 12 hours.
Sincerely,Dev Suрport

​

Some comments have been hidden by the post's author - find out more