OpenAI Agent Builder Vulnerability: Malicious Link Could Create Rogue Agent Taking Orders Every 5 Minutes

The Decoder · rss · 2026-07-24

Security firm Zenity Labs has uncovered a severe vulnerability in OpenAI's Agent Builder, dubbed AgentForger.

By tricking a user into clicking a single tampered ChatGPT link, attackers could create a rogue autonomous agent on their behalf without their knowledge. The agent inherits the victim's identity and access rights, bypasses system approval requirements via malicious prompts, and automatically fetches and executes new destructive instructions from the attacker's inbox every five minutes.

Original post →

More from coding & agent

coding & agent channel →