OpenAI's ChatGPT Workspace Agents vulnerability enables rogue AI agents via phishing link
Security researchers have exposed a critical flaw in OpenAI’s ChatGPT Workspace Agents, dubbed “AgentForger”. The vulnerability resides in the Agent Builder component, where URL parameters can be forged through a cross‑site request forgery (CSRF) attack. By clicking a specially crafted phishing link while logged into ChatGPT, an attacker can automatically create and deploy an autonomous agent inside the victim’s workspace without any further confirmation.
The rogue agent can harvest data from connected services such as Outlook, Gmail, Slack or Teams, disable approval prompts, and persist by scheduling periodic execution. Zenity Labs’ Mike Takahashi highlighted that the attack requires only a single click and works as long as the user has access to Workspace Agents and at least one professional connector. OpenAI released a patch for the issue on 8 June 2026.
The flaw shifts enterprise risk assessment from simple user error to a broader “agent integrity” concern, prompting companies to reevaluate the security model of AI‑driven workflow automation.
Entities: Agent Builder · ChatGPT · Mike Takahashi · OpenAI · Zenity Labs