logo

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

ID: c83dd726-974b-5e76-8c8c-5f33d10f8200

STIX ID: report--c83dd726-974b-5e76-8c8c-5f33d10f8200

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: [email protected] (The Hacker News)

...
...

Zenity Labs disclosed a critical CSRF vulnerability named "AgentForger" in OpenAI's ChatGPT Agent Builder that allowed a single malicious link clicked by an authenticated Workspace user to create and publish an attacker-controlled AI agent within the organization's trust boundary. The crafted URL could inject an initialization prompt that automatically executed, create an agent from a template, attach available connectors and set them to "Never ask" (bypassing user approvals), schedule recurring runs for persistence, and use connected apps to receive commands and exfiltrate data; OpenAI fixed the issue on June 8, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.