Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2024-6587
CVE
CVE-2024-6587
View on NVD ↗
SSRF in berriai/litellm
Exploitation IoCs
1
Domain
chatgpt[.]com
MITRE ATT&CK TTPs
5
T1053.005
Scheduled Task
Execution
T1078
Valid Accounts
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1204.001
Malicious Link
Execution
T1566
Phishing
Initial Access
Source Articles
ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link
A critical vulnerability named AgentForger in OpenAI's ChatGPT Workspace Agents could allow attackers to deploy rogue AI agents via a phishing link. The flaw, a cross-site request forgery (CSRF), enables automatic creation and execution of malicious agents within an authenticated user's session without further interaction. These agents can persist, execute tasks from emails, access enterprise data, and send phishing messages, effectively becoming autonomous insiders.
hacker-news
Jul 24, 2026