hacker-news · Crawled Jul 7, 2026
Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
Read original article ↗AI Summary
A critical session isolation vulnerability in Writer, an enterprise AI platform, dubbed WriteOut, allowed attackers to hijack user accounts across tenants by exploiting the live preview feature. By tricking a logged-in user into clicking a malicious preview link, attackers could steal session cookies and gain full access to the victim's account, including sensitive data and administrative privileges. The vulnerability bypassed input filters by fetching and executing remote malicious scripts within a sandboxed environment.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.