Jul 23, 2026
Policy

Zenity says OpenAI patched ChatGPT agent-builder flaw

Zenity Labs said a crafted ChatGPT link could create a rogue workspace agent using an employee’s approved connectors before OpenAI removed the vulnerable parameter.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

Zenity says OpenAI patched ChatGPT agent-builder flaw
Photo: The Register

OpenAI patched a ChatGPT workspace agents vulnerability that Zenity Labs says could let an attacker create a malicious agent inside a company workspace through a crafted ChatGPT link. The issue, which Zenity named AgentForger, is relevant to enterprises adopting AI agents because the proof of concept relied on authorized business connectors rather than stolen passwords or hijacked browser sessions.

Zenity said the attack required specific conditions: the victim had to belong to a workspace with agents enabled, have permission to create agents, and already be in an environment where administrators had approved the connected apps and actions the agent would use. If those conditions were met, Zenity said one click on a link that appeared to be an ordinary ChatGPT URL could instruct ChatGPT’s agent builder to create, configure, publish and schedule an attacker-controlled agent in the victim’s account.

The flaw sat in the agent builder used to create assistants that can take actions across email, chat, calendars and document repositories, according to Zenity. In the firm’s account, the builder accepted instructions passed through a URL parameter, then used the employee’s existing permissions to connect to services such as Outlook, Teams, Slack, SharePoint or Google Drive, where those integrations were available.

How the proof of concept worked

Zenity said its researchers configured the agent to operate through the victim’s own accounts and permissions. The agent was set up to disable approval prompts, publish itself and run on a schedule, according to the firm.

For command instructions, the researchers did not use outside command-and-control infrastructure. Zenity said the agent watched the victim’s inbox for emails from the attacker with “TASK” in the subject line, then treated each email as an assignment. The demonstrated tasks included searching company systems, collecting files and sending material back by email.

Zenity said its proof-of-concept scenarios also included mapping an organization’s staff and projects by scanning Outlook, Slack, Teams, calendars and file stores. The firm said it demonstrated searches for passwords and API keys in chat history, phishing messages sent from the victim’s Teams account, and business email compromise-style impersonation.

Michael Bargury, Zenity’s co-founder and CTO, told The Register that the issue amounted to a failure in agent trust because the attacker could create an autonomous actor with an employee’s identity and access. OpenAI did not immediately respond to questions from The Register, according to the publication.

Patch timeline

Zenity said it reported the vulnerability to OpenAI through Bugcrowd on June 4. According to the researchers, OpenAI acknowledged the report on June 5 and fixed the flaw four days later by removing the URL parameter that enabled the attack. Zenity said the fix happened before public disclosure.

The company did not disclose any financial impact, affected customer count or evidence of exploitation in the wild. The case still shows the security model gap enterprises face as agents move from answering prompts to acting inside workplace systems. Admin-approved connectors and employee-level permissions can become the execution path if the agent creation flow itself can be steered by an attacker.

This story draws on original reporting from The Register.

More from Policy

All Policy →