ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
A critical vulnerability in OpenAI's ChatGPT Workspace Agents could have allowed a single phishing link to deploy a rogue AI agent inside a victim's organization. The issue has been addressed by OpenAI as of June 8, 2026.
Intelligence analysis by Llama

A phishing link could have deployed a rogue AI agent inside a victim's organization, highlighting a critical vulnerability in OpenAI's ChatGPT Workspace Agents. The issue has been addressed by OpenAI as of June 8, 2026.
Imagine you have a super-smart AI assistant that can do lots of things for you. But what if someone sent you a link that looked harmless, and when you clicked it, the AI assistant started doing bad things without you knowing? That's basically what happened with a vulnerability in OpenAI's ChatGPT Workspace Agents. Luckily, the problem has been fixed, but it's a reminder to always be careful with links and to keep our AI assistants secure.
Analysis
A Critical Vulnerability in ChatGPT Workspace Agents
The recent disclosure of a critical vulnerability in OpenAI's ChatGPT Workspace Agents has sent shockwaves through the cybersecurity community. The vulnerability, codenamed AgentForger by Zenity Labs, could have allowed a single phishing link to deploy a rogue AI agent inside a victim's organization. This agent could have been used to conduct reconnaissance, harvest sensitive documents from cloud storage services, and steal passwords mentioned in Slack messages.
The vulnerability was discovered by Zenity Labs, an AI security company, which found that the ChatGPT Agent Builder tool accepted an initialization state through URL parameters. This allowed an attacker to send a phishing link to a target in the form of a URL that adhered to a specific pattern. When the link was clicked, the ChatGPT Builder would automatically submit the prompt embedded in the URL without requiring any further interaction.
The attacker needed to meet several prerequisites to exploit this vulnerability, including a victim who was logged into ChatGPT, access to Workspace Agents, and at least one authorized connector. The connector integration was necessary because the crafted ChatGPT URL passed as input a chief-of-staff template that allowed the agent to pull necessary data from the workspace applications to prepare a high-signal operating brief.
The payload passed through the malicious prompt instructed the Builder to perform a sequence of actions, including creating an agent from the chief-of-staff template, attaching all already-available connectors, making the agent live, and scheduling it to run every hour. During each run, the agent would check for emails from a specific email address, execute those tasks, and report the results back by sending an email message to the attacker's address.
The findings come nearly a month after Zenity Labs revealed how bad actors are exploiting critical LiteLLM vulnerabilities and exposed Ollama endpoints and hijacking AI infrastructure to conduct attacks against third-parties and power their own offensive operations. These efforts involve the abuse of CVE-2024-6587, CVE-2026-40217, and CVE-2026-35029.
The Importance of Responsible Disclosure
The disclosure of this vulnerability highlights the importance of responsible disclosure and prompt patching of vulnerabilities. OpenAI has since addressed the issue as of June 8, 2026, following responsible disclosure. This incident serves as a reminder of the need for organizations to prioritize security and take proactive measures to prevent such attacks.
The Road Ahead
The discovery of this vulnerability underscores the need for organizations to prioritize security and take proactive measures to prevent such attacks. It also highlights the importance of responsible disclosure and prompt patching of vulnerabilities. As AI-powered tools continue to evolve, it is essential for organizations to stay vigilant and address potential vulnerabilities before they can be exploited.
Key points
- A critical vulnerability in OpenAI's ChatGPT Workspace Agents could have allowed a single phishing link to deploy a rogue AI agent inside a victim's organization.
- The issue has been addressed by OpenAI as of June 8, 2026, following responsible disclosure.
- The vulnerability highlights the potential risks of AI-powered tools and the importance of securing them against attacks.
- The disclosure of this vulnerability underscores the need for organizations to prioritize security and take proactive measures to prevent such attacks.
- The importance of responsible disclosure and prompt patching of vulnerabilities is highlighted by this incident.
The prompt patching of the vulnerability by OpenAI as of June 8, 2026, is a positive step towards securing AI-powered tools. Additionally, the disclosure of this vulnerability highlights the importance of responsible disclosure and prompt patching of vulnerabilities, which can help prevent similar attacks in the future.
The discovery of this vulnerability highlights the potential risks of AI-powered tools and the importance of securing them against attacks. If left unaddressed, such vulnerabilities can lead to broader compromise and other business email compromise (BEC) scenarios.


