AgentForger flaw in ChatGPT could let attackers deploy rogue AI workers
This digest was compiled by AI from multiple sources — links to the originals are below.

Security researchers at Zenity Labs discovered a vulnerability in OpenAI's ChatGPT Agent Builder, dubbed AgentForger, that could allow attackers to deploy malicious AI agents via a single phishing link. The flaw exploited an overly permissive URL parameter to create agents that exfiltrate data without user interaction. OpenAI patched the issue on June 8, 2026, and reported no evidence of exploitation.
The Vulnerability
Zenity Labs discovered AgentForger in OpenAI's ChatGPT Agent Builder, a feature for creating custom AI agents. The flaw stemmed from an overly permissive URL parameter that allowed attackers to craft links embedding arbitrary instructions. Clicking the link would instantly deploy a rogue agent without prompting the victim, enabling data exfiltration or other malicious actions. The agent would persist indefinitely within the organization's infrastructure.
Disclosure and Fix
The researchers disclosed the flaw to OpenAI in early June 2026. OpenAI patched the issue by removing the vulnerable URL parameter on June 8, 2026. No evidence of prior exploitation or abuse was found. Michael Bargury, CTO of Zenity, described the flaw as an 'agent trust failure' that existing security controls were not designed to detect.
What's Next
Organizations using ChatGPT Workspace Agents should verify they are running the patched version. It remains unclear whether similar vulnerabilities exist in other AI agent platforms.
2 sources
AgentForger flaw in ChatGPT could let attackers deploy rogue AI workers


