Solutions  ·  2026-07-24

Zenity Labs discloses 'AgentForger' — cross-site agent forgery in ChatGPT Workspace Agents

SolutionsHigh impactGlobal
Zenity Labs disclosed (July 23, 2026) a critical vulnerability in OpenAI's ChatGPT Agent Builder in which a single crafted URL could silently create, authorize, and deploy an autonomous agent inheriting a victim employee's identity and connector access (email, Slack, Teams, Drive), with approval prompts disabled. OpenAI fixed it within days of Zenity's June 4 report; public disclosure came this week.
Demonstrates a new attack class — 'agent forgery' — where a single click creates a persistent AI insider with real employee privileges, exposing a blind spot in traditional IAM/EDR/DLP tools that don't recognize autonomous agents as distinct actors.
Security teams running ChatGPT Enterprise/Workspace Agents or any agent-builder platform with OAuth-connected tools should audit URL-parameter handling and require agent-creation confirmation now.
Zenity LabsSecurityWeek
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →