ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Zenity Labs disclosed AgentForger, a critical flaw in OpenAI’s ChatGPT Workspace Agents that could let a single phishing link create and deploy an attacker-controlled autonomous agent inside a victim organization. OpenAI fixed the issue on June 8, 2026, after the flaw was shown to abuse URL parameters, connector permissions, and Preview Mode to turn a forged agent into a persistent insider. #AgentForger #OpenAI #ChatGPT #ZenityLabs

Keypoints

  • A phishing link could trigger a CSRF attack against ChatGPT Agent Builder.
  • The flaw could create an AI agent in the victim’s authenticated session.
  • Attackers could attach connectors and disable approval prompts.
  • The forged agent could run on a schedule and execute tasks from email.
  • The agent could steal data, impersonate users, and send phishing messages.

Read More: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html