Back to feed

Vulnerability Discovered in ChatGPT: Attackers Can Infiltrate Teams with Malicious Agents

A cybersecurity firm has discovered a vulnerability in OpenAI's Workspace-Agents feature, allowing attackers to infiltrate teams and steal sensitive data through malicious AI agents.

Vulnerability Discovered in ChatGPT: Attackers Can Infiltrate Teams with Malicious Agents

A cybersecurity firm has uncovered a significant vulnerability in OpenAI's Workspace-Agents feature, which allows attackers to infiltrate teams by creating a malicious AI agent through a fake ChatGPT link. This agent can then continuously steal sensitive information from the organization.

OpenAI introduced the Workspace-Agents tool in April, enabling teams to create AI agents that handle repetitive tasks. However, this functionality has been exploited by cybercriminals, who can effortlessly slip into the system and create an agent that smuggles internal information outside.

Just One Click on a Fake ChatGPT Link

The cybersecurity company Zenity Labs identified this vulnerability and detailed it in a blog post. According to their research, simply clicking on a fraudulent ChatGPT link allows an attacker to infiltrate the system.

Once inside, a malicious actor can create an agent that operates under the guise of the team member who clicked the link, enabling it to extract sensitive data repeatedly. The attacker can program the agent to check incoming emails every five minutes, for example.

AgentForger: A Deceptive Evolution of CSRF

Zenity Labs has named the mechanism enabling these hostile infiltrations "AgentForger." This technique is an advanced iteration of the well-known Cross-Site Request Forgery (CSRF) attack. In typical CSRF attacks, an attacker can only trick their victim into making a single fake request. However, with AgentForger, an agent can be created that continuously performs these actions.

The fake agent can access existing authorizations without the unsuspecting users ever seeing an OAuth consent screen. The malicious URL instructs the system not to request any permissions, allowing the agent to operate undetected.

OpenAI Has Addressed the Vulnerability

Zenity Labs reported the vulnerability to OpenAI in early June. The issue was traced back to a single overly permissive parameter. Just four days later, OpenAI patched the vulnerability. It remains unclear whether any real cybercriminals have exploited this security flaw.

Local AI: No Problem with These 5 Tools