AgentForger Flaw Lets Phishing Links Hijack ChatGPT Agents

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Zenity Labs disclosed a critical cross-site request forgery vulnerability codenamed AgentForger in OpenAI's ChatGPT Agent Builder, which OpenAI patched as of June 8, 2026, following responsible disclosure.
- The crafted ChatGPT link auto-submitted its embedded
initial_assistant_promptandtemplate_nameURL parameters in the victim's authenticated session, requiring no further interaction once clicked. - Exploitation required three prerequisites: a victim logged into ChatGPT, access to Workspace Agents, and at least one already-authorized connector — Outlook, Gmail, Google Calendar, Google Drive, Slack, or Teams.
- The payload built a chief-of-staff template agent, attached all available connectors with approvals switched to 'Never ask,' invoked Preview Mode for immediate execution, and scheduled hourly runs that polled the inbox for 'TASK'-prefixed emails as new instructions.
- OpenAI announced Agent Builder is being deprecated effective November 30, 2026, directing users to migrate to the Agents SDK.
- The implanted agent could impersonate the victim on Teams to distribute phishing links redirecting recipients to fake Microsoft login pages, opening paths to broader business email compromise.
Why it matters: Enterprises that had authorized ChatGPT connectors to email, calendars, and cloud storage effectively handed a single phishing click the keys to workforce data and communications. With only one pre-authorized connector needed and the agent self-scheduling on an hourly loop, any organization piloting Workspace Agents before the June 8 patch faced persistent insider-grade exfiltration risk — and the November 30 deprecation won't retire agents already created and scheduled.




