One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability
One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers ‘AgentForger,’ a ChatGPT Vulnerability
A single link could hijack OpenAI’s ChatGPT Agent Builder to stand up an attacker-controlled AI agent with a real employee’s access and its approvals switched off. Until OpenAI’s fix, any organization using Workspace Agents was exposed.
NEW YORK--(BUSINESS WIRE)--Zenity Labs today disclosed AgentForger, a critical vulnerability in OpenAI’s ChatGPT Workspace Agents that allowed a single phishing link to silently build, authorize and deploy an autonomous AI agent inside a victim’s organization. All it took was one click. An employee opened a normal-looking ChatGPT link, and without a single confirmation, a new AI agent began running inside their company, answering not to the employee but to an attacker. Rather than stealing one session or one file, as most AI attacks do, AgentForger forged an attacker-controlled, agentic insider that fully inherited the victim’s identity.
“With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off." - Michael Bargury, co-founder and CTO of Zenity
Share
The finding highlights a new class of AI security risk in which attackers can create autonomous AI insiders that operate with legitimate employee identity and access.
Once created, the forged agent inherited access to the enterprise applications the employee had already authorized in ChatGPT, including email, calendar, cloud storage, and collaboration tools such as Slack and Teams. It could exfiltrate sensitive data, harvest credentials and MFA tokens, impersonate the employee, and continue operating long after the initial phishing attack. Any organization using ChatGPT Workspace Agents with authorized enterprise connectors was exposed until OpenAI issued its fix.
AgentForger was possible because of a vulnerability in ChatGPT's Agent Builder. Zenity Labs found that attackers could abuse the Agent Builder workflow through a carefully crafted ChatGPT URL to create, authorize, and deploy an autonomous AI agent on behalf of a victim. Rather than stealing a session or a file, AgentForger created a persistent AI insider operating with the victim's identity and enterprise access.
How AgentForger Works
Zenity Labs found that attackers could abuse ChatGPT's Agent Builder by embedding malicious instructions in what appeared to be a normal ChatGPT link. The root cause of this vulnerability lay in a single overpermissive parameter. This parameter allowed anyone to create malicious ChatGPT links that include any instructions. Once clicked, the untrusted instructions were sent to the victim’s own Agent Builder. By leveraging this, an attacker could drive the creation of an entire agent, connect the victim's previously authorized enterprise applications, disable approval prompts, publish the agent, and schedule it to receive ongoing instructions. The result was a persistent AI insider operating with the victim's identity, enterprise access, and instructions from the attacker.
“This isn’t a forged request, it’s a forged insider,” said Michael Bargury, co-founder and CTO of Zenity. “With one click, an attacker gets a fully autonomous agent inside your company that has your people’s identity and access, with the guardrails off. Attackers no longer have to break in to steal your data. They can forge an insider to go get it for them. This is an agent trust failure, and existing security controls were never built to see it.”
Responsible Disclosure
Zenity Labs responsibly disclosed AgentForger to OpenAI through its Bugcrowd vulnerability disclosure program on June 4, 2026. OpenAI acknowledged the report within one day and resolved the issue within four days, removing the URL parameter that originally enabled the attack. The vulnerability was remediated before public disclosure. Zenity Labs applauds the OpenAI security team for the fast turnaround.
Why This Matters
Across a dozen proof-of-concept scenarios, Zenity Labs demonstrated that a forged AI insider could map an organization's environment, harvest sensitive files and credentials, impersonate employees, and launch internal phishing campaigns that created additional compromised agents. Unlike traditional phishing attacks, AgentForger left behind a persistent autonomous agent operating inside the organization.
AgentForger exposes the growing risk introduced by AI agent adoption in the enterprise. As AI agents gain more autonomy and start to take action across email, chat, and cloud storage, a simple implementation mistake or misaligned behavior can have organization-wide consequences. This risk applies to any agent platform. The more an agent can do on its own, the more damage it can cause when it goes rogue, whether influenced by an attacker or independently misbehaving. Traditional security tools were built to monitor users and endpoints, not autonomous agents operating on behalf of a user’s legitimate identity.
AgentForger is the latest in Zenity Labs' ongoing research into the security risks introduced by AI agents. A full technical analysis as well as additional research examining the complete blast radius of a malicious insider agent is available at labs.zenity.io.
Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security. Learn more at https://zenity.io/
Contacts
For Media Inquiries
Elyse Familant
Results PR
Elysef@resultspr.net
