OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

A Critical Flaw in OpenAI’s ChatGPT Workspace Agents Exposes Organizations to Insider Threats

Cybersecurity researchers have uncovered a severe vulnerability in OpenAI’s ChatGPT Workspace Agents, which could allow attackers to create an invisible autonomous agent that can be remotely controlled and used for malicious activities. The flaw, dubbed “AgentForger,” is a tailored cross-site request forgery (CSRF) attack that exploits the Agent Builder’s permissive parameters.

According to Zenity Labs, the researchers who discovered the vulnerability, the issue lies in ChatGPT’s ability to create an agent using a specific template and initial instructions. By embedding two particular parameters in a URL, attackers can trick a user into creating a powerful agent with prespecified instructions that allow for remote control. This includes the ability to automatically accept emails from the attacker as new instructions, effectively turning the agent into a Trojan horse.

The attack relies on a successful phishing attempt against an employee who is logged into ChatGPT and has access to Workspace Agents. The victim must then be socially engineered into clicking the weaponized URL, which directs the agent’s initial steps. These steps can include checking for emails from specific addresses, processing unhandled tasks, and sending results back to the attacker.

“This isn’t a forged request, it’s a forged insider,” comments Michael Bargury, co-founder and CTO at Zenity Labs. “With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off.” This is not just a matter of creating a rogue agent; it’s a failure of trust within the system.

Once created, the attacker can use the invisible agent for reconnaissance, to find sensitive data, harvest credentials, impersonate the victim, deliver internal phishing attacks, and stage Business Email Compromise (BEC) scams. The traditional understanding of CSRF is that it makes the victim’s browser perform a single unintended action; AgentForger takes this to the next level by creating an autonomous system with tools, approvals, instructions, a schedule, and access to already-authorized connectors.

Fortunately, OpenAI has acknowledged the vulnerability and fixed it within three days of being notified. This is a testament to the importance of responsible disclosure and collaboration between researchers and vendors.

For organizations that use ChatGPT Workspace Agents, this vulnerability serves as a reminder of the need for robust security measures to protect against insider threats. While the fix has been implemented, it’s essential to be aware of potential vulnerabilities in AI-powered tools and take proactive steps to ensure trust within their systems. This includes implementing multi-factor authentication, regularly reviewing access controls, and educating employees on social engineering tactics.


Source: SecurityWeek — 2026-07-23