OpenAI Agent Builder Vulnerability: Malicious Link Could Create Rogue Agent Taking Orders Every 5 Minutes
The Decoder · rss · 2026-07-24
Security firm Zenity Labs has uncovered a severe vulnerability in OpenAI's Agent Builder, dubbed AgentForger.
By tricking a user into clicking a single tampered ChatGPT link, attackers could create a rogue autonomous agent on their behalf without their knowledge. The agent inherits the victim's identity and access rights, bypasses system approval requirements via malicious prompts, and automatically fetches and executes new destructive instructions from the attacker's inbox every five minutes.
More from coding & agent
- Dev builds interactive 3D product experience with GPT-6 Astra + Hyper3D Rodin — nikola_mr64990 · 2026-09-11
- Codex tip: use Sol with Astra and Luna sub-agents to save usage — pvncher · 2026-09-11
- agents-best-practices: a provider-neutral Agent Skill for designing and auditing agentic harnesses — tom_doerr · 2026-09-11
- Cognition's SWE-2 uses a KKT duality argument in RL to shift the effort Pareto curve — YouJiacheng · 2026-09-11
- First-ever Three.js Conference lands in Paris, with a panel on AI-shortened design workflows — OdinLovis · 2026-09-11
- Data engineering, not agent frameworks, is the real bottleneck for enterprise AI agents — dhruv2038 · 2026-09-11