AgentForger: one ChatGPT link forged a persistent attacker-controlled agent inside an enterprise workspace
Zenity Labs disclosed AgentForger on July 23 — a cross-site agent forgery flaw in ChatGPT's Agent Builder where two URL parameters (template selector and initial-prompt field) let a single crafted link create, authorize, and activate an invisible agent inside a victim's authenticated workspace with approvals switched off. The forged agent polled an attacker's inbox for new commands every five minutes and could map org structure, exfiltrate documents, harvest credentials, and impersonate the victim across Slack, Teams, and email. OpenAI received the report via Bugcrowd on June 4, confirmed within 24 hours, and removed the vulnerable parameter by June 8; Agent Builder itself is slated for deprecation on November 30, 2026 in favor of the Agents SDK.
Source
↳ Follow the thread