One ChatGPT Link Could Hijack an Employee's Identity and Spawn a Rogue AI Agent

Security firm Zenity Labs has disclosed AgentForger, a vulnerability in OpenAI's ChatGPT Workspace Agents that let a single crafted link silently create, authorize, and launch an autonomous AI agent inside a victim's company, one that answered to the attacker rather than the employee who clicked it.

The attack worked without a single confirmation prompt. If a logged-in employee had already connected at least one enterprise tool, such as Outlook, Gmail, Slack, SharePoint, or Google Drive, to ChatGPT's Agent Builder, a manipulated URL could quietly spin up a new agent, hand it the powerful "Chief of Staff" template, feed it attacker instructions disguised as setup text, and switch off the approval prompts meant to guard sensitive actions. Because the underlying app connections already existed, no OAuth consent screen ever appeared to warn the victim.

Once running, the forged agent inherited the employee's identity and every permission they'd already granted. Zenity says it could rummage through company data, harvest credentials and MFA tokens, send messages impersonating the employee, and keep pulling fresh instructions from the attacker by checking an inbox roughly every five minutes, continuing to operate long after the original phishing link had been clicked and forgotten.

Zenity reported the flaw to OpenAI on June 4; OpenAI removed the vulnerable URL parameter within days, and no evidence has emerged that it was exploited before the fix. Researchers are describing AgentForger as a new attack category rather than a one-off bug: a twist on cross-site request forgery built specifically for AI agents, where the forged object isn't a single unwanted action but a persistent, identity-bearing insider that keeps taking orders. Any organization that had Workspace Agents connected to enterprise tools before the patch was exposed for the duration.