Security researchers at Zenity Labs disclosed “AgentForger,” a cross-site agent forgery flaw in OpenAI’s ChatGPT Workspace Agent Builder that let a single malicious link silently create, configure, and publish an attacker-controlled autonomous agent inside a victim’s authenticated session. The forged agent inherited whatever enterprise access the victim had already granted ChatGPT, including email, calendar, cloud storage, Slack, and Teams, and could poll an attacker’s inbox for commands, exfiltrate data, harvest credentials, and impersonate the employee. OpenAI confirmed the report within 24 hours of its June 4, 2026 disclosure via Bugcrowd and removed the vulnerable URL parameter by June 8; no evidence has surfaced of exploitation before the fix.