OpenAI Agent Builder Vulnerability: Malicious Link Could Create Rogue Agent Taking Orders Every 5 Minutes
The Decoder · rss · 2026-07-24
Security firm Zenity Labs has uncovered a severe vulnerability in OpenAI's Agent Builder, dubbed AgentForger.
By tricking a user into clicking a single tampered ChatGPT link, attackers could create a rogue autonomous agent on their behalf without their knowledge. The agent inherits the victim's identity and access rights, bypasses system approval requirements via malicious prompts, and automatically fetches and executes new destructive instructions from the attacker's inbox every five minutes.
More from coding & agent
- Superwall ships WWDC.ai light mode after a Claude agent rewrites the design — JordanMorgan10 · 2026-07-24
- Agent systems now bottleneck on cost, with configs spanning nearly 1,000x — abeirami · 2026-07-24
- How should an MCP app be designed for non-technical users? — sn0wquake · 2026-07-24
- Greg Kamradt highlights disposable URLs as a new primitive for agent workspaces — GregKamradt · 2026-07-24
- Sentry’s Seer agent answered a Slack question with 30 days of Notion MCP usage data — zeeg · 2026-07-24
- Greg Kamradt says vibe coding raises both the floor and the ceiling — GregKamradt · 2026-07-24