Tampered ChatGPT link spawns rogue attacker-controlled agent
OpenAI Agent Builder vulnerability allows attackers to spawn rogue agents via manipulated links that inherit user permissions.
Zenity Labs uncovered "AgentForger," a vulnerability in OpenAI's Agent Builder that let a single manipulated ChatGPT link create an autonomous agent on an employee's behalf. The agent inherited the victim's identity and access rights, bypassed approval requirements through the malicious prompt, and pulled new instructions from the attacker's inbox every five minutes.
The article One tampered ChatGPT link could spawn a rogue AI agent that took orders from an attacker every five minutes appeared first on The Decoder.