ChatGPT Flaw Let One Link Forge A Rogue AI Agent
Security researchers at Zenity Labs disclosed a critical flaw in OpenAI's ChatGPT Workspace Agent Builder. A single phishing link could pass hidden instructions through a URL parameter that the Builder automatically submitted and executed, creating a live autonomous agent, attaching the victim's already-authorized connectors, and switching off approval requirements. The forged agent inherited access to email, calendar, files, and chat, ran on a recurring schedule, and could be given new tasks by an attacker over email. OpenAI received the report and deployed a fix within four days, with no evidence the flaw was exploited beforehand.
Transcript
A single phishing link could turn ChatGPT's Agent Builder into a hidden employee working for an attacker.
Researchers at Zenity Labs just disclosed a flaw in OpenAI's Workspace Agent Builder. It accepts instructions hidden inside a link.
When a logged-in victim clicks the link, the hidden text runs on its own. It builds an agent and switches approvals off.
The new agent inherits access to the victim's email, calendar, files, and chat. It runs on a schedule as an insider threat.
The attacker then emails new tasks that the agent quietly carries out. OpenAI confirmed the report and patched it within four days.
Quick note: we make Inboxsmith, an AI receptionist that never misses a business call. Get more at inboxsmith dot com. Please like and subscribe for more news.
Sources
Every claim in this video comes from the top ranking coverage of this topic. The claims and where each one came from:
- OpenAI's Workspace Agent Builder automatically submitted and executed instructions embedded in the initial_assistant_prompt URL parameter, letting a single link create an autonomous agent with approvals disabled and pre-authorized connectors attached.(AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery (Zenity Labs))
- The forged agent inherited access to email, calendars, files, and messaging, ran on a recurring schedule, and enabled command-and-control by executing tasks dispatched via email to the compromised account.(AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery (Zenity Labs))
- OpenAI patched the vulnerability within four days, receiving the report on June 4, 2026 and deploying the fix by June 8, 2026, with no evidence of exploitation before the fix.(AgentForger, Part 1: ChatGPT Cross-Site Agent Forgery (Zenity Labs))
- Codenamed AgentForger, the attack used the chief-of-staff template, scheduled hourly runs watching for TASK-prefixed emails, abused Preview Mode to execute live, and could impersonate the victim to send phishing links via Teams.(ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link (The Hacker News))
