Skip to content

ChatGPT Vulnerability Enabled Installation of Autonomous AI Agents in Enterprise

In brief: Attackers exploited a CSRF flaw to inject autonomous AI agents with employee privileges into ChatGPT and automate email exfiltration; the vulnerability was patched within three days.

Zenity Labs discovered the AgentForger vulnerability in OpenAI’s ChatGPT Workspace Agents, which allowed attackers to create specially configured AI agents via manipulated URLs that could receive commands from external email addresses. OpenAI remediated the flaw within three days of disclosure.

The AgentForger vulnerability was rooted in a specific form of Cross-Site Request Forgery (CSRF) in ChatGPT’s Agent Builder. Attackers could hijack the agent creation process by manipulating two parameters in an initialization URL: the first parameter selected a template, the second passed instructions directly to the creation process. Using the Chief-of-Staff template and automated startup commands, it was possible to create a prepared agent that responded to commands from an external email address.

Exploitation required an already-authorized user with access to Workspace Agents and connected interfaces such as Gmail or Outlook to click on a prepared link. Since authorization already existed, no OAuth confirmation dialog was displayed. The created agent then operated in the background, executing commands sent via email. Michael Bargury, co-founder and CTO of Zenity Labs, characterized the security implication precisely: this created not merely a phishing request, but an automated insider attacker operating with the compromised employee’s access rights and bypassing existing security controls.

The installed agent could specifically process unread messages, extract data, and transmit it unencrypted to the attacker’s address. This would have made it possible to exfiltrate email contents, attachments, and other information stored in the connected services without detection by traditional network intrusion detection systems or data loss prevention solutions.

Zenity Labs disclosed the vulnerability to OpenAI confidentially on June 4. The vendor confirmed the finding within one day and fully remediated the flaw through an adjustment to parameter processing in the Agent Builder on June 8. The rapid patch management prevented an extended exploitation window in the production environment.


Source: www.it-daily.net · Published 27 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: