OpenAI patched 'AgentForger' ChatGPT workspace flaw that let one link create a malicious AI agent inside company accounts

Researchers say a single malicious ChatGPT link could plant an attacker-controlled AI agent inside a company’s ChatGPT workspace and make it act with an employee’s access. Zenity Labs said the flaw, dubbed AgentForger, affected OpenAI’s workspace agent builder and let a crafted URL silently create, configure, publish, and schedule a rogue agent that could use approved connectors such as Outlook, Teams, Slack, SharePoint, and Google Drive. OpenAI reportedly fixed the issue in June 2026 by removing the vulnerable URL parameter.
Why it matters: This matters because it turns a normal phishing click into a persistent insider-style foothold that can search company data, send messages as an employee, and continue operating after the initial lure. Organizations using ChatGPT workspace agents should review agent-creation permissions, connected app access, and logs for unexpected agents or scheduled tasks.

Sources

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
Kevin Townsend 2026.07.23 98% relevant
This article is a direct report on the same AgentForger vulnerability, adding detail on the attack chain: abuse of Agent Builder URL parameters, use of the Chief of Staff template and initial_assistant_prompt, invisibility conditions, and post-compromise uses such as recon, credential harvesting, internal phishing, and business email compromise.
One ChatGPT link could smuggle a rogue AI agent into your company
2026.07.23 100% relevant
This article appears to be the first tracked report of the specific OpenAI 'AgentForger' workspace-agent vulnerability and its phishing-based abuse path.
← Back to all stories