AgentForger: a simple ChatGPT link could inject a malicious AI agent into your workspace

In this saga : Agents IA autonomes : nouveau vecteur d'attaque à l'échelle du swarm· Episode 7/7

Cybersecurity 1 h agoAdd to bookmarks

AgentForger: a simple ChatGPT link could inject a malicious AI agent into your workspace

Zenity Labs publicly disclosed on July 23, 2026 a vulnerability in the ChatGPT agent builder that allowed the silent installation of a malicious agent inheriting all of the victim's connectors (Outlook, Slack, Drive...). Fixed on June 9 - but the vulnerability class remains to be monitored.

The Facts

On July 23, 2026, Zenity Labs publicly disclosed AgentForger, a vulnerability that exploited the agent builder of ChatGPT to silently install a malicious agent in a victim's workspace. The flaw was reported to OpenAI on June 4, 2026 via Bugcrowd, acknowledged on June 5, and fixed on June 9 by removing the vulnerable URL parameter. Public disclosure occurred on July 23. No CVE has been assigned to date.

How It Worked

An attacker prepared a malicious link containing URL parameters that triggered the agent builder without visible interaction. By clicking, the victim initiated the following chain:

  1. The builder ran in the background.
  2. An agent automatically configured itself, inheriting connected services in the workspace: Outlook, Teams, Slack, SharePoint, Google Drive.
  3. Approval prompts were disabled.
  4. The agent was published and then scheduled.
  5. It monitored the victim's email: every message with the subject containing the keyword "TASK" became a new command - file search, data exfiltration, sending messages on behalf of the employee.

Michael Bargury, co-founder and CTO of Zenity, summarizes the attack as "a fully forged insider; the attacker no longer needs to enter to steal your data."

Who Is Affected

OpenAI ChatGPT workspaces where three conditions were met:

  • agents are enabled in the workspace;
  • the user has the right to create agents;
  • third-party applications (Outlook, Slack, Drive…) have been approved by an administrator.

What to Do

The vulnerable URL parameter has been removed by OpenAI, so the exploit described is no longer usable as-is. However, the class of vulnerabilities it illustrates - the manipulation of an agent builder by a simple link, with automatic inheritance of permissions - remains a vector to watch closely.

To Do Now

1. Audit the list of agents published in your ChatGPT workspaces and remove any agent you do not recognize. 2. Restrict agent creation to accounts that truly need it. 3. Review Connected Apps and remove unnecessary integrations.

Analysis

We have been following a series of incidents for several months with a common point: the compromise no longer targets the code of the AI application, but the execution framework of the agent - delegated permissions, connectors, prompts. AgentForger fits into this line alongside the Hugging Face breach linked to an autonomous agent and the manipulation of review agents in Azure DevOps MCP. The pattern is clear: when an agent inherits a bunch of already approved permissions, it becomes a risk multiplier, and the attack surface shifts from "how to inject code" to "how to forge a legitimate agent."

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

7 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information