OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider
AgentForger allows an attacker to create, insert and remotely control an invisible autonomous AI agent inside a victim organization. The post OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider appeared first on SecurityWeek.
Zenity Labs has found and disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, which it names AgentForger; a tailored cross-site request forgery (CSRF). With a single successful phish, an unsuspecting employee could be tricked into launching an invisible autonomous agent that is remotely controlled by the attacker.
Zenity explains in two blogs (Part 1 and Part 2) that the vulnerability was in ChatGPT’s Agent Builder allowing an over permissive parameter. Researchers found that the official agent build process could be usurped from within an initialization URL using two particular parameters. One names the agent template to be used, while the other (initial_assistant_prompt) provides instructions to the Builder. The first parameter, using the Chief of Staff template, builds a more powerful and flexible agent than other templates. The latter contains instructions that are automatically submitted and executed. More specifically, the ‘initial prompt’ can become the first command the Builder acts on.
With these two parameters embedded in the URL, the attacker can generate a powerful agent with prespecified instructions. One of the instructions exploiting this process is to automatically accept emails from the attacker as new instructions, allowing the attacker to control the agent remotely.
Related breach coverage
- OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability2026-07-20
Attackers could send waves of malicious payloads to trigger buffer pre-allocations that are not freed, exhausting server memory. The post OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability appeared first on SecurityWeek.
- RabbitMQ Vulnerability Threatens Enterprise Systems2026-07-13
Unauthenticated attackers could obtain the broker's confidential OAuth client secret, allowing them to take control of the broker. The post RabbitMQ Vulnerability Threatens Enterprise Systems appeared first on SecurityWeek.
- Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft2026-07-22
An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared first on SecurityWeek.
- Fresh SharePoint Vulnerability Exploited Soon After Disclosure2026-07-17
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
