CVE Tools
Back to feed
Patch released ChatGPT Workspace Agents ai-ml OpenAI phishing

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Researchers at Zenity Labs have revealed a critical cross-site request forgery (CSRF) vulnerability in OpenAI's ChatGPT Workspace Agents, codenamed AgentForger. This flaw could have enabled attackers to create and deploy unauthorized AI agents within an organization using a simple phishing link. The vulnerability was responsibly disclosed and patched by OpenAI on June 8, 2026. If exploited, the flaw would allow an attacker to forge an AI agent with full access to connected enterprise tools like Outlook, Gmail, Slack, and more—without requiring additional user interaction after the initial click. The affected product, Agent Builder, is now being deprecated by OpenAI.