Security researchers at Zenity Labs described a flaw in ChatGPT's Workspace Agents builder that let a single crafted link create and publish an automated agent inside a victim's account without further clicks. The link carried instructions that turned off approval prompts, attached already-connected apps such as Outlook and Slack, and set the agent to run on a repeating schedule so an attacker could send it tasks by email. It required the victim to be signed in with a connector already authorized, and OpenAI fixed the issue four days after it was reported in June 2026.
What changed
Creating a ChatGPT Workspace Agent was assumed to require the user to choose a template, write instructions, approve connected tools and publish it deliberately.
What it unlocks
Defenders can check whether unexplained scheduled Workspace Agents exist in their tenant and review which connectors were left without approval prompts.
- fixed within 4 days of disclosure
- reported 4 June 2026, fixed 8 June 2026
- scheduled runs every 5 minutes
What you need to act on it
- a victim logged into ChatGPT with access to Workspace Agents
- at least one connector such as Outlook or Slack already authorized
Sources