Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

0
Low
Vulnerabilityremote
Published: 07/23/2026 (07/23/2026, 15:09:59 UTC)
Source: SecurityWeek

Description

A critical vulnerability named AgentForger was discovered in OpenAI's ChatGPT Workspace Agents that allowed attackers to create and remotely control an invisible autonomous AI agent inside a victim organization. The flaw exploited an over permissive parameter in the Agent Builder via a tailored cross-site request forgery (CSRF) attack. By tricking a logged-in employee with access to Workspace Agents and authorized connectors into clicking a malicious URL, an attacker could deploy an autonomous agent that executes attacker-supplied commands invisibly. The agent could process attacker emails as instructions, perform actions using connected apps, and send results back to the attacker without detection. OpenAI was notified and fixed the vulnerability within four days of disclosure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/23/2026, 15:22:19 UTC

Technical Analysis

The AgentForger vulnerability in OpenAI's ChatGPT Workspace Agents involved a CSRF attack exploiting two URL parameters in the Agent Builder: one specifying the agent template and another providing the initial assistant prompt. Using the Chief of Staff template and a crafted initial prompt, an attacker could create a powerful autonomous agent that automatically accepted commands via email and operated invisibly within the victim's environment. The attack required a successful phishing click by an employee logged into ChatGPT with access to Workspace Agents and at least one authorized connector (e.g., Gmail or Outlook), enabling the agent to act without triggering new OAuth consent. Once created, the agent could autonomously execute attacker instructions, harvest data, impersonate users, and conduct internal phishing or business email compromise activities. Zenity Labs reported the flaw to OpenAI, which fixed it within three days after acceptance. This vulnerability represents an agent trust failure allowing attackers to forge an insider AI agent with authorized access and no user approval prompts.

Potential Impact

The vulnerability allowed attackers to create an invisible, autonomous AI agent inside a victim organization that operated with the victim employee's identity and access privileges. This agent could be remotely controlled via attacker emails to perform reconnaissance, data harvesting, credential theft, impersonation, internal phishing, and business email compromise. The attack bypassed traditional security controls by leveraging authorized connectors and existing user sessions, making detection difficult. The presence and actions of the agent were invisible to the victim organization, effectively forging an insider threat without requiring direct system compromise.

Mitigation Recommendations

OpenAI has fixed the vulnerability within three days of disclosure. Organizations using ChatGPT Workspace Agents should ensure they are running the updated, patched version. Since this is not a cloud service vulnerability, users must apply the official fix provided by OpenAI. No additional mitigation steps are indicated by the vendor advisory. Patch status is confirmed fixed as of June 8, 2026.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/","fetched":true,"fetchedAt":"2026-07-23T15:22:06.909Z","wordCount":1398}

Threat ID: 6a62319e9c2644c7f846dde0

Added to database: 07/23/2026, 15:22:06 UTC

Last enriched: 07/23/2026, 15:22:19 UTC

Last updated: 07/23/2026, 20:03:38 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses