ChatGPT Flaw AgentForger that could be Exploited by Hackers
Share
As per cybersecurity professionals, ChatGPT’s Workspace Agent Builder can be tricked to create rogue AI agents. For your information, Agent Builder enables users to make custom AI agents. Zenity Labs found a flaw in Agent Builder which has been given a name – “AgentForger”. The latter permits any entity to create ChatGPT links which have no restrictions on included instructions.
Extremely High Potential of Substantial and Long Duration Damage
Upon clicking the link, the latter dispatches instructions to Agent Builder without intimating the user. This is a new security risk in which malicious entities can make AI agents that have legitimate user identity as well as access. The agent has access to each of the applications the user had previously authorized in ChatGPT such as email, calendar, cloud services and collaboration applications including Teams as well as Slack. The former could dispatch confidential information to the attacker, gather credentials as well as MFA tokens. Also, it could assume the identity of the user and operate long after the original phishing action.
Turns of User Approval Feature in Order to be Undetected
The rogue agent would switch off the user approval needed feature as well as execute attacker commands. The flaw has been fixed by OpenAI with the fix applied on June 8. As per Zenity because of the vulnerability a URL could automatically make, authorize as well as activate a rogue AI agent inside a user’s authenticated ChatGPT workspace. For the attack to take place the user had to be logged into ChatGPT. Also, user should have permission to use Workspace Agents. Thirdly the user should already have minimum one authorized enterprise connector like Microsoft Teams, Slack, Google Drive, Google Calendar, Gmail or Outlook.
Flaw Successfully Eliminated
The flaw was fixed by deleting the URL parameter that allowed the attack. There are no reports that the flaw was detected and exploited by malicious entities.
FAQs
- What is the ChatGPT AgentForger flaw?
The ChatGPT AgentForger flaw is a security weakness that researchers say could allow hackers to manipulate AI agents into performing actions they were not supposed to do. Instead of directly attacking a computer, the attacker tries to trick the AI into following harmful instructions or bypassing safety rules.
- How could hackers exploit the AgentForger flaw?
Hackers could create specially designed prompts or malicious content that confuses an AI agent. If successful, the AI might reveal sensitive information, perform unauthorized actions, or interact with websites and services in ways that benefit the attacker.
- Are everyday ChatGPT users at immediate risk?
For most everyday users, there is no need to panic. The AgentForger issue mainly affects AI agents that are connected to external tools, websites, or business systems. However, users should still avoid sharing sensitive personal or financial information with AI services unless they trust the platform.
- What can organizations do to reduce the risk?
Organizations can reduce the risk by regularly updating AI systems, limiting what AI agents are allowed to access, monitoring AI activity, and testing their systems for security weaknesses. Human oversight for important tasks also helps prevent misuse.
- Does the AgentForger flaw mean ChatGPT is unsafe?
No. The discovery of the AgentForger flaw does not mean ChatGPT is generally unsafe. It highlights the importance of continuously improving AI security. Security researchers regularly identify and report such issues so developers can strengthen protections and make AI systems more secure over time.
SOURCES:-
https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
https://tech.yahoo.com/ai/chatgpt/articles/experts-warn-chatgpts-workspace-agent-120500195.html
https://www.01net.it/one-click-one-attacker-controlled-agentic-insider-zenity-labs-uncovers-agentforger-a-chatgpt-vulnerability/
https://www.ibtimes.sg/critical-chatgpt-flaw-could-have-let-hackers-secretly-plant-rogue-ai-agents-enterprise-workspaces-90659
https://streamlinefeed.co.ke/news/chatgpt-agentforger-flaw-rogue-ai-agent-security
https://www.csoonline.com/article/4200978/agentforger-proves-ai-agents-can-become-persistent-insider-threats.html
