type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, technique, sector-technology] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Zenity Labs disclosed a CSRF vulnerability in OpenAI's ChatGPT Workspace Agents (codenamed AgentForger) that allowed a single phishing link to build, authorise, and deploy an attacker-controlled AI agent inside a victim's organisation. Fixed by OpenAI on 8 June 2026.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 (disclosure) |
| Vulnerability Type | Cross-Site Request Forgery (CSRF) |
| Product | OpenAI ChatGPT Workspace Agents |
| Codename | AgentForger |
| Discoverer | Zenity Labs |
| Fixed by | OpenAI (8 June 2026) |
Attack Chain
- Victim clicks a crafted phishing link
- The link triggers a CSRF request to the victim's ChatGPT Workspace
- An attacker-controlled AI agent is automatically built, authorised, and deployed
- The rogue agent has access to the organisation's ChatGPT workspace data and tools
Impact
This vulnerability allowed attackers to bypass organisational access controls and deploy persistent AI agents within a victim's workspace, capable of exfiltrating data or performing actions on behalf of the organisation.
Related Pages
- Hacker Runs Hermes Ai Agent Unattended For Post Exploitation At Thai Finance Min โ AI agent used offensively against a government target