Critical Vulnerability in OpenAI’s ChatGPT Workspace Agents Exposed
A shocking flaw in OpenAI’s ChatGPT Workspace Agents, dubbed AgentForger by researchers, has left organizations vulnerable to a sophisticated attack that can turn an unsuspecting employee into a remote-controlled AI insider. The vulnerability, which was discovered and disclosed by Zenity Labs, allows attackers to create a powerful autonomous agent with pre-specified instructions, completely invisible to the victim organization.
The attack relies on social engineering, where an attacker tricks a victim employee into clicking a malicious URL while logged into ChatGPT and possessing access to Workspace Agents. This URL embeds two critical parameters: one names the agent template to be used, and the other provides instructions to the Builder. The Chief of Staff template is particularly potent, as it builds a more powerful and flexible agent than other templates.
Once created, the invisible agent can perform a range of malicious actions on behalf of the attacker, including reconnaissance, harvesting credentials, impersonating the victim, delivering internal phishing attacks, and even staging Business Email Compromise (BEC) scams. The agent’s instructions are delivered via emails with a subject starting with ‘TASK’, which it undertakes autonomously.
“This isn’t a forged request, it’s a forged insider,” comments Michael Bargury, co-founder and CTO at Zenity Labs. “With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off.” The severity of this vulnerability lies in its ability to exploit existing security controls, which were never designed to detect such an attack.
Fortunately, OpenAI responded promptly to Zenity Labs’ findings, accepting them within a day and fixing the vulnerability within three days. AgentForger was disclosed on June 4 and fixed on June 8. However, this incident highlights the growing need for organizations to reassess their security posture in light of emerging threats from autonomous agents.
As we move forward in this era of AI-driven cybersecurity, it is essential that organizations prioritize robust security measures to prevent such attacks. One practical takeaway from this incident is the importance of educating employees on phishing and social engineering tactics, as well as implementing robust security protocols to detect and prevent unauthorized access to sensitive systems. By staying vigilant and proactive, we can mitigate the risks associated with these emerging threats and protect our organizations from becoming unwitting hosts to AI insiders.
Source: SecurityWeek — 2026-07-23