ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
Summary
OpenAI's ChatGPT Workspace Agents had a critical vulnerability called AgentForger that allowed attackers to use a single phishing link to secretly create and deploy a rogue AI agent inside a victim's organization. The flaw exploited cross-site request forgery (CSRF, a type of attack where a malicious website tricks your browser into making unwanted requests) by embedding malicious instructions directly in a URL that would automatically execute when a logged-in employee clicked it, giving the attacker's agent access to the victim's connected apps like email and cloud storage without requiring approval.
Solution / Mitigation
OpenAI addressed the issue as of June 8, 2026, following responsible disclosure. Additionally, OpenAI announced it is deprecating the Agent Builder product effective November 30, 2026, and urging users to switch to the Agents SDK.
Classification
Affected Vendors
Related Issues
Original source: https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
First tracked: July 24, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%