Security researchers from Zenity Labs revealed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed attackers to install a fully autonomous AI agent inside a company’s environment using just one crafted link. The flaw could grant external actors persistent, insider-level access to corporate systems via ChatGPT’s Agent Builder platform.
Discovery by Zenity Labs
Zenity Labs, an Israeli cybersecurity firm focused on AI-related attack surfaces, discovered the issue within ChatGPT’s Agent Builder—a tool enabling companies to create workflow-capable agents inside their internal ChatGPT workspaces. The vulnerability, dubbed AgentForger, exploited two URL parameters within the builder’s initialization step.
One parameter allowed selection of the agent template, which defaulted to a highly privileged “Chief of Staff” agent. The second, named initial_assistant_prompt, could be used to input instructions that were implemented automatically as soon as the Agent Builder loaded in the browser. When chained together, these manipulated parameters let an attacker create a link. If a user already logged into ChatGPT Workspace Agents clicked it, the system would silently spin up an autonomous agent tied to that person’s account and access privileges, set to check the attacker’s commands every five minutes and execute them without detection.
Mini dictionary: Zenity Labs—a cybersecurity company specialized in securing enterprise AI tools and preventing attacks related to AI platforms and agents.
Risks and Potential Impact
Unlike a typical cross-site request forgery—where a single unauthorized action is triggered—AgentForger resulted in the establishment of a fully operational, persistent agent that impersonated an employee with legitimate access. Zenity Labs co-founder and CTO Michael Bargury emphasized the significance of the threat, stating that this approach enabled attackers to plant an “autonomous agent inside your company that has your people’s identity and access.”
Michael Bargury described the situation as far more serious than a simple forged request, noting that a single click could provide attackers with sustained access, acting as a ‘forged insider’ with disabled guardrails.
For the exploit to succeed, the targeted employee needed to be logged into ChatGPT with Workspace Agents enabled and at least one enterprise connector, such as Outlook, Gmail, Slack, or SharePoint, pre-authorized. No additional security prompts warned users of unusual activity in this scenario. Zenity Labs demonstrated that attackers could use the rogue agent to exfiltrate documents, map internal structures, steal credentials, and impersonate victims across connected platforms.
| Attack Requirement | Traditional Phishing | AgentForger Exploit |
|---|---|---|
| User Interaction | Click link, enter credentials | Click single crafted link |
| Access Level | Limited, one-time | Persistent, full employee access |
| Detection | Noticeable (login prompt) | Invisible (no prompt) |
Response and Remediation
Zenity Labs disclosed the vulnerability to OpenAI via the Bugcrowd program on June 4, 2026. OpenAI confirmed the report the next day and released a security fix by June 8, removing the dangerous URL parameter handler. Both organizations stated they found no evidence the vulnerability had been exploited before mitigation.
OpenAI further announced it would deprecate the legacy Agent Builder tool on November 30, 2026, shifting users toward its newer Agents SDK and Workspace Agents interface for improved safety.
Wider Security Context
Security professionals have begun referring to vulnerabilities like AgentForger as part of a ‘lethal trifecta’: accepting untrusted inputs, connecting to sensitive internal data, and permitting unmonitored data exfiltration. This combination can turn the helpful automation of AI agents into significant risks for organizations.
Unlike recent incidents involving AI models circumventing system boundaries or breaking sandbox controls, AgentForger demonstrates how attackers can exploit the trust built into agent platforms, particularly when convenience features like instant setup and pre-authorized connectors are present. Researchers expect to see ongoing scrutiny as more companies transition to autonomous agent platforms with deep integration across enterprise environments.
The AgentForger exploit is being viewed as a sign of larger, structural risks as the adoption of agent-builder tools accelerates, with industry experts warning that attack surfaces will likely expand in the coming years.





USDT
AAPL
