Researchers at Zenity Labs disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that allowed attackers to deploy rogue autonomous AI agents through phishing links. The flaw, codenamed AgentForger, enabled adversaries to bypass authorization controls and build fully functional agents within victim organizations without explicit consent.

The attack chain required minimal interaction. A victim clicked a malicious link, which triggered automated agent creation and authorization within the ChatGPT Workspace environment. Once deployed, the rogue agent gained access to organizational data and could perform actions on behalf of the compromised user account.

The vulnerability exploited insufficient validation in ChatGPT's agent provisioning workflow. OpenAI's system failed to properly verify user intent during agent creation, allowing attackers to escalate privileges through social engineering alone. No additional authentication or administrative approval blocked deployment.

Organizations using ChatGPT Workspace Agents faced direct risk. Attackers could establish persistence within corporate environments, exfiltrate sensitive information, manipulate workflows, or abuse agent integrations to access connected services and databases. The autonomous nature of agents meant compromised instances operated independently after initial deployment.

Zenity Labs reported the flaw to OpenAI, which addressed the vulnerability on June 8. The remediation likely introduced stricter authorization requirements and additional verification steps during agent creation. OpenAI has not disclosed technical specifics about the patch or confirmed whether active exploitation occurred in the wild.

This incident reflects growing risks in AI agent ecosystems. As organizations deploy autonomous agents for business automation, security gaps in agent provisioning and authorization create new attack surfaces. Users should update to the patched version immediately and review recent agent deployments for unauthorized instances. Organizations should also enforce strict access controls on ChatGPT Workspace and implement email security measures to block phishing attempts targeting agent creation workflows.