OpenAI Fixes Agent Flaw After ChatGPT Workspace Insider Risk
SecurityWeek reported that OpenAI fixed the AgentForger flaw in ChatGPT Workspace Agents after Zenity Labs showed how a phishing link could create a hidden autonomous agent with access to already-authorised connectors.

A hidden AI agent inside a company account changes the risk profile of ordinary phishing because the compromised object is not just a browser session or password.
SecurityWeek reported that OpenAI fixed a ChatGPT Workspace Agents flaw after Zenity Labs showed how a crafted link could create an autonomous agent with access to already-authorised connectors.
Zenity Labs named the flaw AgentForger and classified it as a tailored cross-site request forgery issue in ChatGPT's Agent Builder.
The exposure depended on a victim employee being logged into ChatGPT, having Workspace Agents access and already-authorised connectors such as Gmail or Outlook, so the attack path did not require a new OAuth consent screen.
The affected feature sits in ChatGPT Workspace Agents, where business accounts can connect productivity apps before an agent acts across the workspace.
Agent Builder Became The Trust Boundary
The agent-creation step gave the bug its enterprise weight.
Zenity's disclosure described parameters in an initialisation URL as a way to preconfigure the build process and supply the first instructions the Builder acted on.
The resulting agent could be made difficult for the organisation to see and could receive later directions through connected apps.
Zenity's disclosure framed that as an autonomous system with tools, approvals, a schedule and access to already-authorised connectors, which moves the exposure beyond conventional CSRF.
Security teams normally treat CSRF as an unintended action performed through a user's browser.
AgentForger pushed that action into agent creation: the system that was created could keep operating after the original click, use the victim's authorised connectors and return data through the connected workflow.
OpenAI Fixed The Bug In Three Days
SecurityWeek reported that Zenity disclosed AgentForger on June 4 and OpenAI fixed it on June 8.
The same account put OpenAI's acceptance of the findings within a day and the repair window at three days.
The short repair window narrows the immediate product exposure, but the incident still gives enterprise AI buyers a clearer failure mode to test.
Admin controls, connector permissions, approval prompts and agent visibility all become security controls when an AI workspace can act across email or productivity systems.
The product consequence is specific: a workspace agent inherits trust from the user and the connector before it performs work.
If an attacker can influence the build process, the organisation must detect not only suspicious logins or malicious files, but also unauthorised agent creation, hidden schedules and unexpected connector use.
Connector Access Raises The Response Burden
Zenity's account of the flaw included possible abuse paths such as reconnaissance, sensitive-data discovery, credential harvesting, internal phishing, impersonation and business email compromise.
Those outcomes depended on the permissions and connectors already available to the victim account.
The remediation lesson is not to publish more detailed attack steps.
Security teams need evidence that agent builders, connector grants and scheduled actions are visible in logs, can be reviewed by administrators and can be revoked when a phished user has authorised access to sensitive apps.
OpenAI's fix closes the disclosed AgentForger path, while the public record does not show whether affected Workspace customers received customer-specific exposure findings or whether similar agent-builder flows have been audited across other enterprise AI tools.


















