AgentForger Vulnerability Lets Attackers Smuggle Rogue AI Agents into ChatGPT Workspaces
Key Takeaways
- ▸A single ChatGPT link could create a fully autonomous, attacker-controlled agent within a company's ChatGPT workspace without the victim's knowledge
- ▸The agent could act on behalf of the employee using their permissions, connected services, and credentials across email, chat, and file storage systems
- ▸The vulnerability exemplifies how AI agents connected to corporate infrastructure dramatically expand the attack surface for social engineering and data theft
Summary
Security researchers at Zenity Labs discovered a critical vulnerability in OpenAI's ChatGPT workspace agents, dubbed "AgentForger," that allowed attackers to silently create malicious autonomous agents within a victim's account through a single phishing link. The flaw exploited OpenAI's agent builder by accepting specially crafted instructions embedded in ChatGPT URLs, enabling attackers to configure and deploy agents that could leverage employee credentials and connected services like Outlook, Teams, Slack, and SharePoint. Once activated, the rogue agent could operate autonomously—accessing corporate data, impersonating employees, and receiving commands via specially formatted emails—effectively creating a "corporate mole" that persisted long after the initial attack. OpenAI acknowledged the report on June 5 and patched the vulnerability four days later by removing the vulnerable URL parameter.
- OpenAI patched the flaw within four days of being notified, but the incident reveals fundamental security gaps in agent-based systems
Editorial Opinion
The AgentForger vulnerability represents a critical inflection point for AI security—it's not just about the model itself, but autonomous agents operating within trusted corporate environments with legitimate employee access. This attack doesn't require breaking firewalls or stealing credentials; instead, it weaponizes trust by turning an employee's own AI assistant into an insider threat. As enterprises integrate agents into workflow systems, organizations need entirely new detection and prevention frameworks to catch compromised AI—not just compromised humans.



