Zenity Labs has uncovered a significant vulnerability within OpenAI’s ChatGPT Workspace Agents, termed AgentForger. This vulnerability, a tailored cross-site request forgery, could allow attackers to create and remotely control invisible AI agents within organizations. By tricking an employee into clicking a malicious link, an attacker could launch an autonomous agent that operates under the radar.
The flaw resided in ChatGPT’s Agent Builder, where an over permissive parameter allowed attackers to manipulate the agent creation process. By embedding two specific parameters in an initialization URL, attackers could use the powerful Chief of Staff template to create an agent and provide it with instructions for further actions. These instructions included accepting emails as new commands, effectively enabling remote control by the attacker.
The attack requires the victim to be logged into ChatGPT with access to Workspace Agents and authorized connectors like Gmail or Outlook. This setup allows the agent to become operational without triggering new consent screens. Once activated, the agent can conduct reconnaissance, find sensitive data, harvest credentials, and impersonate the victim. The attacker's emails, marked with a specific subject line, direct the agent's actions and return results to the attacker.
Zenity reported this vulnerability to OpenAI, which promptly acknowledged the issue and patched the system within three days. AgentForger was disclosed on June 4 and fixed by June 8, highlighting OpenAI’s rapid response to security threats.


