ChatGPT AgentForger Vulnerability Allowed Rogue AI Agent Deployment
- CVE ID
- N/A
- Affected Products / Orgs
- OpenAI ChatGPT Workspace Agents
A newly disclosed security flaw in OpenAI’s enterprise AI platform allowed attackers to silently deploy rogue agents inside an organization’s workspace through a single malicious interaction. Codenamed AgentForger by researchers at Zenity Labs, the ChatGPT Workspace Agents vulnerability exploited session and authorization handling to grant unauthenticated actors execution capabilities inside victim enterprise environments.
How the AgentForger Attack Functions
The attack required a victim with active workspace credentials to click a specially crafted phishing link. Upon interaction, the link leveraged cross-origin session context to silently execute administrative requests against OpenAI’s agent configuration endpoints.
Without displaying consent prompts or requiring additional confirmation from the user, the sequence executed the following actions behind the scenes:
- Constructed a hidden custom AI agent within the victim’s ChatGPT Workspace tenant.
- Assigned the new agent permissions inherited from the victim’s active organizational session.
- Deployed the autonomous agent into an active state, making it available to accept remote instructions.
Once deployed, the rogue agent operated autonomously, enabling an attacker to issue commands externally and access internal enterprise data or trigger integrated API capabilities using the victim’s authorized identity.
Enterprise Risks of Autonomous Agent Exploitation
As organizations deploy agentic AI tools to automate business operations, agent authorization boundaries become critical attack targets. Traditional session riding and request forgery techniques gain increased impact when applied to autonomous systems: once instantiated, an unauthorized agent acts as a persistent internal actor capable of performing multi-step actions across connected enterprise apps.
AgentForger highlights the security challenge posed by complex AI integration layers, where missing explicit consent validation during agent creation can completely bypass standard identity controls.
Resolution and Governance Measures
OpenAI resolved the vulnerability on June 8 by modifying the authorization controls for Workspace Agent creation endpoints, ensuring that agents cannot be instantiated or granted access without explicit, interactive user consent. Security administrators managing enterprise ChatGPT deployments should review their tenant audit logs and inspect active workspace agents to verify that no rogue configurations were created prior to the patch.
Related content
OpenAI Cuts GPT-5.6 Luna and Terra API Costs, Launches Sol Fast Mode
Security NewsOpenAI Cuts GPT-5.6 API Costs and Introduces Sol Fast Mode
Security NewsOpenAI Previews Astra AI Model After Breakthroughs in Math and Lattice Cryptography
Security NewsOpenAI Teases Astra AI Model Built for Complex Workloads and Cryptography
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call