16-Year-Old Hacker Exposes Supply Chain Attack on AI Documentation Platform Affecting Tech Giants

A 16-year-old high school security researcher discovered a critical cross-site scripting (XSS) vulnerability in the AI documentation platform Mintlify, which could allow attackers to steal user credentials through malicious scripts. The vulnerability affected several major tech companies including Discord, X (Twitter), Vercel, and Cursor. The researcher successfully exploited the static file serving functionality to bypass security restrictions by embedding malicious scripts in SVG files after analyzing Mintlify’s API endpoints. This incident reveals the security risks in AI tool supply chains, demonstrating the cascading effects that a single component vulnerability can trigger. The researcher has responsibly disclosed the vulnerability to affected companies and received a total of approximately $11,000 in security bounties.

Original link:Hacker News

C code80.ai · AI 编码 API 聚合 Claude / GPT 多模型统一接入,稳定不限速,按量计费,几行配置接入 Claude Code。 了解一下 ›

抢沙发

评论前必须登录!

立即登录   注册