What is this vulnerability and how serious is it?
A security vulnerability was identified in Salesforce Agentforce, which potentially enabled external attackers to exfiltrate CRM data through a sophisticated indirect prompt injection attack. Malicious data containing concealed instructions could be submitted by attackers, which could then be executed when employees subsequently interact with said data via AI agents, potentially leading to the exposure of sensitive information. This attack vector posed a significant threat due to its delayed nature, allowing it to remain dormant until activated by routine employee interactions. Upon activation, the injected payload would execute within the context of the running user: for Agent Service Agent, this would typically be the user under which the agent operates; for employee agents, it would be the organizational user interacting with the agent. This could have led to the disclosure of potentially sensitive information, contingent on the data accessibility of the executing user and the configured actions of the payload.