OpenAI's 'AgentForger' Vulnerability Exposed Corporate AI Agents to Malicious Hijacking
Key Takeaways
- ▸A single click on a crafted ChatGPT link could install a rogue AI agent inside a company's workspace with full access to employee identity and connected services
- ▸Malicious agents could autonomously steal data, impersonate employees, and execute ongoing attacks by receiving instructions via email
- ▸The vulnerability exploited the agent builder's URL parameter mechanism, which failed to validate the legitimacy of configuration instructions
Summary
Security researchers at Zenity Labs discovered a critical vulnerability in OpenAI's ChatGPT workspace agents that would have allowed attackers to create and deploy malicious autonomous agents inside corporate workspaces with a single phishing link. The flaw, dubbed "AgentForger," exploited the agent builder's ability to accept embedded instructions through URL parameters, enabling attackers to silently configure, publish, and schedule rogue agents that could impersonate employees and abuse their access permissions.
Once activated, the malicious agents could leverage any pre-authorized integrations such as Outlook, Teams, Slack, SharePoint, and Google Drive to infiltrate sensitive corporate systems. The agents were designed to operate autonomously—checking the victim's email inbox for messages with "TASK" in the subject line and executing attacker commands to exfiltrate data, impersonate employees, and launch business email compromise attacks. The guardrails protecting these connections were effectively disabled, transforming connected employees into unwitting conduits for corporate espionage.
Zenity disclosed the vulnerability to OpenAI on June 4, 2026, and OpenAI patched the flaw four days later by removing the malicious URL parameter before public disclosure. The incident underscores a fundamental security gap: as AI agents gain the ability to execute actions across enterprise systems and connected applications, traditional security controls designed to prevent external intrusions are blind to threats that exploit legitimate internal capabilities.
- OpenAI patched the flaw on June 8, 2026, but the incident reveals that AI agent proliferation in enterprise systems creates entirely new attack surfaces
Editorial Opinion
The AgentForcer vulnerability exposes a critical gap in enterprise AI security: as organizations integrate AI agents deeper into their workflows, they're unwittingly creating insider-threat attack surfaces that existing security infrastructure was never designed to defend against. The fact that a single phishing link could instantiate a fully autonomous, permission-aware mole inside a company highlights a troubling asymmetry—defenders must protect against all attack vectors, while attackers only need to find one crack in the foundation. As AI agents evolve from passive information tools to active corporate participants with persistent access to email, files, and communication platforms, the industry needs to rethink both how agents are deployed and how organizations monitor their behavior.



