Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, technique, sector-technology] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Zenity Labs disclosed a CSRF vulnerability in OpenAI's ChatGPT Workspace Agents (codenamed AgentForger) that allowed a single phishing link to build, authorise, and deploy an attacker-controlled AI agent inside a victim's organisation. Fixed by OpenAI on 8 June 2026.

Overview

Attribute Detail
Date 2026-07-24 (disclosure)
Vulnerability Type Cross-Site Request Forgery (CSRF)
Product OpenAI ChatGPT Workspace Agents
Codename AgentForger
Discoverer Zenity Labs
Fixed by OpenAI (8 June 2026)

Attack Chain

  1. Victim clicks a crafted phishing link
  2. The link triggers a CSRF request to the victim's ChatGPT Workspace
  3. An attacker-controlled AI agent is automatically built, authorised, and deployed
  4. The rogue agent has access to the organisation's ChatGPT workspace data and tools

Impact

This vulnerability allowed attackers to bypass organisational access controls and deploy persistent AI agents within a victim's workspace, capable of exfiltrating data or performing actions on behalf of the organisation.

Related Pages