Severity: CriticalVulnerabilityPrompt injection
Critical vulnerability in ChatGPT Workspace Agents enables unauthorized agent deployment via phishing
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
Researchers identified a critical flaw in OpenAI's ChatGPT Workspace Agents that could allow an attacker to construct, authorize, and deploy a rogue AI agent within an organization using a single malicious link. The vulnerability, dubbed AgentForger, was patched by OpenAI as of June 8.
What to do
Ensure users upgrade ChatGPT Workspace to the patched version and educate teams on recognizing suspicious agent authorization prompts.
Mapped framework pillars
Sources
#ChatGPT#workspace agents#phishing#unauthorized deployment#agent compromise#privilege escalation
