One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes
Back to Home
security

One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes

July 23, 20265 views2 min read

Security researchers have found a critical vulnerability in OpenAI's Agent Builder that allows attackers to create rogue AI agents using a single compromised ChatGPT link.

Security researchers have uncovered a critical vulnerability in OpenAI's Agent Builder that could allow attackers to create rogue AI agents with persistent access to corporate systems. Zenity Labs identified a flaw dubbed AgentForger, which enables a single compromised ChatGPT link to spawn an autonomous agent on behalf of an employee, effectively hijacking their identity and privileges.

How the Exploit Works

The vulnerability lies in how Agent Builder handles user prompts and access control. By manipulating a ChatGPT link, an attacker can trick an employee into initiating a malicious agent. This agent, once created, inherits the user's access rights and can execute actions without further approval. The most alarming aspect is that the agent pulls new instructions from the attacker's inbox every five minutes, allowing for continuous, automated malicious activity.

Implications and Response

This flaw presents a severe risk to enterprise AI security, especially as more organizations adopt AI-powered tools for automating workflows and decision-making. The ability to run a persistent, autonomous agent with elevated privileges means that a single phishing click could lead to long-term system compromise. OpenAI has been notified, but as of now, no official patch or mitigation strategy has been released. Security experts are urging organizations to review their AI tool configurations and implement stricter access controls to prevent such attacks.

The discovery of AgentForger underscores the growing need for robust security frameworks around AI systems, particularly those that enable agent creation and automation. As AI tools become more integrated into business operations, the potential attack surface expands, making vulnerabilities like this a critical concern for enterprises and security teams alike.

Source: The Decoder

Related Articles