// ChatgptCRITICAL
Zenity Labs disclosed AgentForger, a critical CSRF vulnerability in ChatGPT Workspace Agents that allows attackers to create and remotely control invisible autonomous agents via malicious URLs sent through phishing attacks. The vulnerability exploited overpermissive parameters in the Agent Builder initialization process. OpenAI has patched the flaw.
- OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge a(opens in a new tab)
- ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via(opens in a new tab)
// Get alerts for Chatgpt