Zenity Labs disclosed AgentForger, a critical CSRF flaw in OpenAI’s ChatGPT Workspace Agents that could let a phished employee unknowingly create an invisible autonomous agent controlled by an attacker. The attack could abuse ChatGPT Agent Builder parameters to hide the agent, accept attacker emails as commands, and enable covert access to sensitive data and internal actions. #AgentForger #OpenAI #ChatGPT #ZenityLabs
Keypoints
- Zenity Labs found a critical CSRF vulnerability in ChatGPT Workspace Agents.
- The flaw could be exploited through a weaponized initialization URL.
- Attackers could force the Agent Builder to create a hidden autonomous agent.
- The agent could treat attacker emails as instructions and execute tasks remotely.
- OpenAI fixed the issue within three days after Zenity reported it.