AIToday
Large Language ModelsAI Safety & AlignmentTHE DECODERPublished: Jul 24, 2026, 04:02 JST

OpenAI Agent Builder flaw lets one malicious link spawn rogue AI agent

OpenAI Agent Builder flaw lets one malicious link spawn rogue AI agent

Zenity Labs discovered "AgentForger," a vulnerability in OpenAI's Agent Builder that allowed a single manipulated ChatGPT link to create an autonomous agent impersonating an employee. The agent inherited the victim's identity and access rights, bypassed approval requirements through a malicious prompt, and retrieved new instructions from the attacker's inbox every five minutes.

Not sure about something? Ask the AI

Summaries like this, in your inbox every morning.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • GPT-6 Astra cracks 83-year-old Enigma message, says Bloomberg developerTHE DECODER · 2h ago
  • Discover Labs: AI search makes the LLM the new website visitorPractical AI · 2h ago
  • OpenAI says internal model cracked Navier–StokesLast Week in AI · 2h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleOpenAI AI hacks Hugging Face—but trust in AI labs at historic low