Particle.news

OpenAI Fixes AgentForger Flaw That Could Forge Invisible AI Insiders

The company removed a permissive link parameter after researchers showed a single click could create a persistent agent that uses existing email connectors as a remote control channel.

Overview

  • Security researchers at Zenity Labs found a critical AgentForger bug in ChatGPT’s Workspace Agent Builder that let a crafted link supply an agent template and an initial prompt that the Builder would execute automatically.
  • The vulnerability let an attacker embed instructions in a URL so a clicked link could create a live agent, attach already-authorized connectors like Gmail or Outlook, disable approval prompts, and schedule persistent runs.
  • Successful exploitation required specific conditions: a victim logged into ChatGPT, access to Workspace Agents, at least one pre-authorized connector, and a tricked click on the weaponized URL.
  • Zenity disclosed the issue on June 4 and OpenAI removed the risky initialization URL parameter on June 8, and reporters say there is no public evidence the flaw was abused before the patch.
  • The episode highlights an 'agent trust' gap for enterprises and security teams should log and audit agent creation, review connector grants and OAuth scopes, tighten phishing defenses, and apply least-privilege controls for connectors.