MCP 0.0.0.0 Day Vulnerability
Salesforce Agentforce was susceptible to a critical indirect prompt injection vulnerability, codenamed ForcedLeak (CVSS 9.4). This flaw allowed attackers to exfiltrate sensitive CRM data by manipulating Web-to-Lead forms, causing AI agents to transmit information to an attacker-controlled domain.
STABLE
What Happened
Salesforce Agentforce was susceptible to a critical indirect prompt injection vulnerability, codenamed ForcedLeak (CVSS 9.4). This flaw allowed attackers to exfiltrate sensitive CRM data by manipulating Web-to-Lead forms, causing AI agents to transmit information to an attacker-controlled domain.
Why This Matters
Publisher reporting describes a security event affecting MCP. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether MCP is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Sep 25, 2025 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: DEMONSTRATED
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2025-49596: 4 public repository references found.
Possible public PoC reference
PoC for CVE-2025-49596 on linux targets
0 stars ยท Python
Open repositorySecurity advisory / research reference
A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities using Ed25519-signed CapabilityCards, mandatory mTLS, Keycloak IdP authentication, and per-call ephemeral Docker sandboxing.
1 stars ยท TypeScript
Open repositorySecurity advisory / research reference
MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint responds to unauthenticated requests, indicating a potential security flaw. The script is simple to use and provides clear output on whether the target server is likely vulnerable or patched.
0 stars ยท Python
Open repositoryPublic GitHub reference
Browser-based MCP CTF โ OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.
0 stars ยท JavaScript
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Jul 01, 2025 05:30BugSkan first recorded this incident.
-
Critical Vulnerability in Anthropic's MCP Exposes Developer Machines to Remote Exploits - The Hacker News
Jul 01, 2025 05:30thehackernews.com ยท Vulnerability
-
The MCP Security Survival Guide: Best Practices, Pitfalls, and Real-World Lessons - Towards Data Science
Aug 06, 2025 05:30towardsdatascience.com ยท Vulnerability
-
Salesforce AI Agents Forced to Leak Sensitive Data - Dark Reading | Security
Sep 25, 2025 05:30darkreading.com ยท Data Leak
-
Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection - The Hacker News
Sep 25, 2025 05:30thehackernews.com ยท Vulnerability
-
Latest observed development
Sep 25, 2025 05:30Most recent source or update associated with this incident.
Sources
thehackernews.com ยท Jul 01, 2025 05:30
A critical remote code execution (RCE) vulnerability, CVE-2025-49596 (CVSS 9.4), has been identified in Anthropic's Model Context Protocol (MCP) Inspector, exposing developer machines to compromise. Attackers can exploit this by chaining a browser flaw dubbed "0.0.0.0 Day" with a CSRF vulnerability in the Inspector, leveraging default settings that lack authentication and encryption.
Open publisher sourcetowardsdatascience.com ยท Aug 06, 2025 05:30
The article details critical security vulnerabilities within Model Context Protocol (MCP) deployments, including a remote code execution exploit (CVE-2025-49596) affecting exposed MCP Inspector tools. It also outlines how malicious OAuth proxying, leveraging the "Confused Deputy Problem," can lead to user impersonation and unauthorized access to third-party services.
Open publisher sourcedarkreading.com ยท Sep 25, 2025 05:30
Researchers discovered "ForcedLeak," a critical indirect prompt injection vulnerability (CVSS 9.4) within Salesforce's Agentforce AI platform. This exploit enables attackers to embed malicious instructions into web forms, compelling the autonomous agent to exfiltrate sensitive CRM data, including PII and corporate secrets, to attacker-controlled domains.
Open publisher sourcethehackernews.com ยท Sep 25, 2025 05:30
Salesforce Agentforce was susceptible to a critical indirect prompt injection vulnerability, codenamed ForcedLeak (CVSS 9.4). This flaw allowed attackers to exfiltrate sensitive CRM data by manipulating Web-to-Lead forms, causing AI agents to transmit information to an attacker-controlled domain.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.