ZENITY Labs disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace, known as AgentForger. This vulnerability involves a cross-site request forgery (CSRF) that could allow an attacker to create an invisible autonomous agent controlled remotely. The vulnerability stems from an over-permissive parameter in the ChatGPT Agent Builder, which can be exploited using two specific parameters embedded in a malicious URL.
If an employee, logged into ChatGPT and authorized with connectors like Gmail or Outlook, is tricked into clicking this link, the attacker gains access to sensitive actions and data without raising any visible alarms. Once operational, the agent can autonomously receive and process commands via email from the attacker, and relay results back, facilitating unauthorized data access. Zenity reported the flaw to OpenAI, which fixed it within three days of disclosure.