Affected Systems

OpenAI ChatGPT Workspace Agents (Agent Builder tool) used by organizations with connected enterprise apps (Outlook, Gmail, Google Drive, Slack, Teams, Google Calendar). Vulnerability patched June 8, 2026. Agent Builder deprecated effective November 30, 2026.

Exploitation Status

No evidence of active exploitation reported. Vulnerability disclosed responsibly by Zenity Labs and patched by OpenAI as of June 8, 2026. Proof-of-concept demonstrated by researchers.

Business Impact

Cross-site request forgery (CSRF) vulnerability allowed attackers to deploy persistent, autonomous AI agents within victim organizations via phishing link. Forged agents could execute hourly, access connected enterprise apps without approval prompts, exfiltrate sensitive documents from cloud storage, harvest credentials from Slack messages, conduct reconnaissance, and send phishing messages impersonating victims. Attack required victim to be logged into ChatGPT with Workspace Agents access and at least one authorized connector. No CVE assigned. Severity rated critical by researchers.

Urgency

🟡 Within a week

Recommended Actions

  • Verify OpenAI ChatGPT Workspace Agents are updated to post-June 8, 2026 version; confirm patch status with OpenAI support if uncertain.
  • Audit all ChatGPT Workspace Agents in your organization for unauthorized or suspicious agents created between vulnerability window and June 8, 2026 patch date.
  • Review connector approval settings for existing ChatGPT agents; ensure 'Never ask' approval mode is only enabled for legitimate, verified agents.
  • Plan migration from deprecated Agent Builder to Agents SDK before November 30, 2026 deadline; prioritize organizations with high-privilege connector integrations.
  • Implement email filtering rules to detect and quarantine emails with 'chatgpt.com/agents/studio/new' URLs containing 'initial_assistant_prompt' parameters; alert security team on matches.
  • Conduct user awareness training on AI agent phishing risks; emphasize verification of unexpected ChatGPT links even from trusted domains.