Connect with us

Cybersecurity

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Published

on

A critical security vulnerability in OpenAI’s ChatGPT Workspace Agents could have allowed attackers to deploy malicious AI agents inside an organization’s workspace using nothing more than a specially crafted phishing link, according to new research from AI security firm Zenity Labs.

The vulnerability, dubbed AgentForger, has already been patched by OpenAI following responsible disclosure, with the company resolving the issue on June 8, 2026.

One Click Could Create a Malicious AI Agent

Researchers found that the flaw could be exploited through a carefully designed ChatGPT URL containing hidden instructions.

If a logged-in employee clicked the phishing link, ChatGPT’s Agent Builder could automatically execute the embedded instructions, allowing an attacker to create, configure, authorize, and activate a rogue AI agent within the victim’s organization—all without requiring additional user interaction.

The attack exploited a Cross-Site Request Forgery (CSRF) vulnerability that enabled unauthorized actions to be performed using the victim’s authenticated ChatGPT session.

Vulnerability Affected Workspace Agents

The issue involved ChatGPT’s Agent Builder, a visual tool that allows users to create automated AI workflows connected to enterprise applications.

According to Zenity, the Builder accepted initialization parameters directly from specially crafted URLs. Instead of simply displaying these values in the interface, the application automatically processed and executed them when the page loaded.

This behavior enabled attackers to embed malicious prompts inside phishing links, effectively instructing the platform to create a fully functional AI agent under the victim’s account.

Attack Required Specific Conditions

Researchers noted that several conditions needed to be met for a successful attack.

The victim had to:

  • Be logged into ChatGPT.
  • Have access to Workspace Agents.
  • Already have enterprise connectors configured, such as Outlook, Gmail, Google Drive, Google Calendar, Slack, or Microsoft Teams.

If these requirements were satisfied, the attacker could leverage existing trusted integrations without requesting additional approvals.

Rogue Agent Could Operate Continuously

The malicious instructions were designed to create an AI agent using an existing enterprise workflow template before automatically attaching all available connectors.

The attack then configured the agent to bypass future approval requests, publish itself, schedule recurring execution, and immediately launch in Preview Mode.

Researchers explained that Preview Mode was not merely a simulation. Instead, it executed the newly created agent using the victim’s connected enterprise applications and available permissions.

Once activated, the rogue agent could repeatedly monitor the victim’s email inbox for specially formatted commands from the attacker, execute those instructions, and return results through email—effectively creating a persistent AI-controlled backdoor.

Access to Sensitive Enterprise Data

According to Zenity, the compromised AI agent could perform numerous actions depending on the permissions granted through connected enterprise applications.

Potential capabilities included:

  • Collecting sensitive documents from cloud storage.
  • Reading business emails.
  • Searching collaboration platforms for confidential information.
  • Extracting passwords shared in workplace conversations.
  • Gathering intelligence about internal systems.
  • Executing attacker-provided instructions automatically.

Because the agent operated using the victim’s legitimate permissions, many of its actions could appear to be normal business activity.

Potential for Internal Phishing Campaigns

Researchers also warned that the rogue AI agent could impersonate employees by sending phishing messages through workplace collaboration platforms such as Microsoft Teams.

Recipients could then be redirected to fake login pages designed to steal corporate credentials, potentially allowing attackers to expand their access across an organization and facilitate business email compromise (BEC) attacks.

Unlike traditional phishing campaigns, the attacker would not need additional interaction after the initial click. Once installed, the AI agent could continue receiving new commands through email while operating autonomously.

OpenAI Patched the Issue

Zenity disclosed the vulnerability responsibly, and OpenAI addressed the flaw on June 8, 2026, preventing malicious URLs from automatically executing instructions within Agent Builder.

The issue affected the now-deprecated Agent Builder, which OpenAI has announced will be retired by November 30, 2026, with users encouraged to transition to the newer Agents SDK.

AI Security Risks Continue to Grow

The disclosure comes amid increasing concern over the security of enterprise AI platforms and autonomous agents.

Zenity noted that attackers are increasingly targeting AI infrastructure, agent frameworks, and self-hosted AI services to gain persistent access, automate malicious activities, and exploit misconfigured enterprise environments.

Security experts recommend that organizations carefully review AI agent permissions, limit unnecessary connector access, educate employees about phishing attempts targeting AI tools, and continuously monitor autonomous workflows for unexpected behavior.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO