news.mlab.sh
Back to the feed
threat-intel

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

Critical
Summary

A critical session isolation vulnerability, dubbed WriteOut, has been discovered in Writer, an AI platform, allowing attackers to steal session tokens and gain control of user accounts across multiple organizations. The flaw stems from a misconfiguration in the live preview feature, enabling attackers to hijack accounts simply by sharing a public preview link. Writer has since patched the vulnerability, but the incident highlights a significant risk for organizations utilizing the platform.

The vulnerability, identified by Sand Security, centers around Writer's live preview functionality. Users can share a public preview link, and when a logged-in user clicks this link, their browser automatically attaches their Writer session cookie to the request. This allows a malicious agent, hosted by the attacker, to intercept the cookie and gain access to the victim's account. The issue bypasses traditional tenant isolation protections because the attacker doesn't need to be part of the same organization as the victim. The attack chain involves the attacker creating a malicious agent and sharing its preview link, followed by the victim’s browser sending their session cookie to the attacker’s sandbox, where the attacker can then replay the token and take full control.

Read the full article at The Hacker News