Zenity Discloses Patched ChatGPT Workspace Agent Vulnerability Zenity Labs publicly disclosed AgentForger on July 23 after OpenAI fixed a ChatGPT Workspace Agents vulnerability on June 8, four days after Zenity reported it via Bugcrowd. The flaw allowed a weaponized link to create, publish, and schedule an attacker-controlled agent under a victim's existing workspace permissions and connectors, though Zenity found no evidence of exploitation in the wild. Zenity Discloses Patched ChatGPT Workspace Agent Vulnerability Zenity Labs publicly disclosed AgentForger on July 23 after OpenAI fixed the ChatGPT Workspace Agents vulnerability on June 8, four days after it was reported. Zenity says a weaponized link could create, publish and schedule an attacker-controlled agent under a victim's existing workspace permissions and connectors; the company says it found no evidence of exploitation in the wild. Zenity Labs publicly disclosed AgentForger on July 23, after OpenAI fixed the ChatGPT Workspace Agents vulnerability on June 8. Zenity reported the flaw through Bugcrowd on June 4, and OpenAI accepted it the following day. The researchers said a weaponized ChatGPT link could drive the Agent Builder to create, configure, publish and schedule an attacker-controlled agent under a victim employee's existing workspace identity. Zenity says it found no evidence that the vulnerability was exploited in the wild. How the attack worked Zenity described AgentForger as a tailored cross-site request forgery. The Agent Builder accepted initialization state from two URL parameters: one selected a template, while initial assistant prompt supplied instructions that the builder automatically submitted and executed. A successful attack required several conditions. The target had to be logged into ChatGPT, have access to Workspace Agents, and hold permission to create agents. At least one enterprise connector, such as Gmail or Outlook, also had to be authorized already, and the workspace's administrator settings had to permit the connected applications and actions involved. In Zenity's proof of concept, a single click caused the builder to attach existing connectors, change approval settings, publish the agent and set recurring schedules. The forged agent then monitored the employee's inbox for messages from an attacker with TASK in the subject line. Those messages could instruct it to search connected files and communications, collect data, send internal messages or email results externally, subject to the victim's permissions and workspace controls. Why the flaw mattered The attack did not depend on stealing a password or taking over a browser session. It attempted to turn an authenticated user action into a durable software actor that continued invoking enterprise tools through preexisting permissions. That distinction broadens the security boundary for agentic systems. Controls over agent creation, connector scope, approval settings, scheduled execution and publication can be as consequential as controls over initial authentication. Monitoring also needs to distinguish legitimate automation from a new agent acting through a real employee's identity and approved connectors. Zenity's disclosure says OpenAI fixed the issue within four days of the report. The available sources do not describe the technical implementation of the patch or identify additional remediation that customers must perform. For teams operating comparable platforms, the practical checks are to inventory agents and their connected applications, restrict who can create or publish agents, review actions allowed without approval, and monitor unexpected schedules or email-triggered workflows. The incident shows why lifecycle controls must cover how an agent is created, authorized, changed and retired, not only how its prompts are filtered. Key Points - 1Zenity reported AgentForger on June 4, OpenAI accepted it on June 5 and fixed it on June 8 before the July 23 public disclosure. - 2The proof of concept combined URL-driven agent creation, existing enterprise connectors, changed approval settings and scheduled email-based tasking. - 3Agent platforms need lifecycle controls over creation, connector scope, approvals, publication and monitoring because autonomous workflows can persist after the initial click. Scoring Rationale The issue affected a widely used enterprise AI platform and demonstrated a high-consequence attack path through delegated identity and connected business applications. It is especially relevant to practitioners deploying autonomous agents with SaaS connectors, although Zenity reported no evidence of exploitation in the wild. Sources Primary source and supporting public references used for this report. View 4 more sources AgentForger: Why AI Agent Security Needs More Than a Patchzenity.io https://zenity.io/blog/product/chatgpt-agentforger One ChatGPT link could smuggle a rogue AI agent into your companytheregister.com https://www.theregister.com/security/2026/07/23/one-chatgpt-link-could-smuggle-a-rogue-ai-agent-into-your-company/5275116 OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insidersecurityweek.com https://www.securityweek.com/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/ OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insideritsecuritynews.info https://www.itsecuritynews.info/openai-fixes-chatgpt-agent-flaw-that-could-let-attackers-forge-an-ai-insider/ Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems