AgentForger: Why AI Agent Security Needs More Than a Patch
This secondary product account links to the technical research. It is preserved with attribution; exact exploit validation, advisory scope and the original technical disclosure must be independently checked before minting a new vulnerability entry.
This secondary product account links to the technical research. It is preserved with attribution; exact exploit validation, advisory scope and the original technical disclosure must be independently checked before minting a new vulnerability entry.
What the source establishes
Zenity describes AgentForger as a disclosed ChatGPT Workspace Agents flaw that allowed a link to create an autonomous agent with inherited employee access and disabled approval prompts. It says OpenAI fixed the flaw and reports no evidence of exploitation in the wild.
Moona assessment and evidence limits
This secondary product account links to the technical research. It is preserved with attribution; exact exploit validation, advisory scope and the original technical disclosure must be independently checked before minting a new vulnerability entry.
Verification scope
Moona reviewed the retained source on 29 September 2026. Source acquisition and review establish provenance for this account; they do not reproduce an experiment, validate a vendor deployment or authorize an action.
Sources
This analysis interprets third-party reporting, research and announcements. Moona is not the original reporter of the underlying events.
