Researchers at Zenity Labs disclosed AgentForger, a vulnerability in OpenAI's ChatGPT Workspace Agents Builder that allowed a single attacker-crafted ChatGPT link to silently create and publish a malicious AI agent inside a victim's authenticated corporate workspace. The issue affected users who were logged into ChatGPT, had access to workspace agents, and had administrator-approved connectors or actions available. According to the disclosure, the flaw abused URL parameters including template_name and initial_assistant_prompt, causing security-sensitive instructions to be auto-submitted and executed instead of presented for review, effectively creating a CSRF-style cross-site agent forgery attack.
Once deployed, the forged agent could inherit the victim's connected services and permissions across tools such as Outlook, Gmail, Slack, Teams, Google Drive, and SharePoint, disable approval prompts, schedule recurring execution, and use the victim's mailbox as a command channel. Zenity said the rogue agent could search corporate data, map internal projects and personnel, extract sensitive documents and credentials, send messages as the employee, and conduct internal phishing or fraud through trusted collaboration platforms before exfiltrating results by email. OpenAI was notified through Bugcrowd on June 4 and fixed the issue by June 8 by removing the vulnerable URL parameter before the public disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Zenity publicly disclosed AgentForger and published research detailing how a malicious ChatGPT link could forge and deploy an autonomous insider-like agent in corporate ChatGPT workspaces. The disclosure included technical details on exploitation, persistence, command-and-control via email, and potential abuse of enterprise connectors.
OpenAI remediated the AgentForger vulnerability by June 8, 2026, including removing the vulnerable URL parameter path that enabled silent agent creation and deployment. The fix came four days after Zenity's initial report.
OpenAI acknowledged Zenity's Bugcrowd report about the AgentForger issue. This acknowledgment followed the initial disclosure of the workspace agent vulnerability.
Zenity researchers reported the AgentForger vulnerability in OpenAI's ChatGPT Workspace Agents to OpenAI through Bugcrowd. The flaw allowed a malicious ChatGPT link to silently create and deploy an attacker-controlled agent in a victim's authenticated workspace session.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcethehackernews.com
Open sourcelabs.zenity.io
Open sourcetheregister.com
Open sourcelabs.zenity.io
Open sourcelabs.zenity.io
Open sourceopenai.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.