Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants
ID: a10dbbed-04d5-534e-aa05-2881cccf27c4
STIX ID: report--a10dbbed-04d5-534e-aa05-2881cccf27c4
Feed Name: The Hacker News
Researchers disclosed a critical session-isolation vulnerability dubbed **WriteOut** in the Writer enterprise AI platform that allowed an attacker to weaponize public live-preview links to forward and exfiltrate victim session tokens from a managed sandbox, enabling cross-tenant account takeover and access to chats, documents, private models, connectors, and potentially administrative control; Writer remediated the issue by removing session cookies from sandbox previews, migrating previews to an isolated origin, and reported the fix was applied within 24 hours with no evidence of customer data compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
