« All posts

AgentForger: ChatGPT URL Param Exploit Creates Rogue Workspace Agents

A vulnerability in ChatGPT's Agent Builder allowed unauthorized agent creation via URL parameters, raising security concerns for engineers.

Zenity Labs revealed a vulnerability in ChatGPT's Agent Builder, where URL parameters could be exploited to create unauthorized Workspace Agents. When a crafted link is clicked by a logged-in user, it could silently attach pre-authorized connectors and publish the agent without additional permissions. This incident highlights significant security risks in agentic AI systems, prompting a need for better logging and monitoring practices.

This synthesis was produced from its source by AI; there is no human editor or manual review step. How we work