ChatGPT AgentForger Flaw Spawns Persistent Rogue Agents

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Zenity Labs disclosed the AgentForger vulnerability in OpenAI's ChatGPT Workspace Agents, a cross-site request forgery (CSRF) flaw that lets a single phishing link build, authorize, and deploy an autonomous AI agent inside a victim's organization.
- OpenAI patched the flaw as of June 8, 2026, following responsible disclosure; Zenity's Mike Takahashi identified that Agent Builder auto-executes the initial_assistant_prompt URL parameter without any user interaction.
- Exploitation requires three prerequisites: a victim logged into ChatGPT, Workspace Agents access, and at least one authorized connector such as Outlook, Gmail, Google Calendar, Google Drive, Slack, or Teams.
- The forged agent is configured to attach all available connectors, set approvals to "Never ask," and run hourly, then waits for emails with "TASK" in the subject line to execute attacker instructions and report results back.
- Once live, the rogue agent can harvest cloud documents, scrape passwords from Slack messages, and impersonate the victim on Teams to send phishing links, including fake Microsoft login pages for credential theft.
- OpenAI announced last month it is deprecating the Agent Builder product effective November 30, 2026, directing users to migrate to the Agents SDK — meaning the vulnerable product has roughly five months of life remaining.
- The findings follow Zenity's earlier disclosure of attackers abusing LiteLLM and exposed Ollama endpoints via CVEs 2024-6587, 2026-40217, and 2026-35029 to hijack AI infrastructure for offensive operations.
Why it matters: AgentForger is an agent trust failure at its core: the platform assumes the user intentionally created and approved each agent, but one click bypasses that entirely. Because the forged agent is scheduled hourly against the victim's real enterprise connectors with approvals switched off, it functions as a persistent insider that turns the victim's own mailbox into a command channel — and can pivot to BEC-style phishing from inside Teams before anyone notices.




