We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
TL;DR Highlight
Mintlify's AI docs platform had an internal endpoint validation gap that allowed injecting malicious JavaScript into customer domains like discord.com and docs.x.com.
Who Should Read
Security engineers reviewing SaaS platforms with white-label or custom domain features, and frontend security practitioners.
Core Mechanics
- Mintlify hosts documentation for major tech companies (Discord, X, etc.) and allows custom domains — the vulnerability let an attacker inject arbitrary JavaScript into those customer-owned domains.
- The root cause was insufficient validation of internal API endpoints that were accessible with lower privilege levels, allowing content injection that bypassed CSP for affected domains.
- The injected scripts could steal session tokens, perform phishing, or exfiltrate data from users of the affected documentation sites.
- The scope was significant: any visitor to the affected documentation pages (including enterprise customers' internal docs) could have been targeted.
- Mintlify patched the issue after responsible disclosure, but the exploit window is unknown.
Evidence
- The researcher provided a working proof-of-concept showing malicious JS executing on docs.x.com and discord.com domains.
- HN commenters noted this is a common class of vulnerability in white-label SaaS — the aggregation risk of one platform serving many high-value domains.
- Concern was raised about supply chain implications: documentation sites often load third-party analytics, fonts, and chat widgets — an XSS here could pivot to those.
- Several security engineers noted the specific risk of doc site XSS: developers are often logged in to internal tools while reading docs, making session hijacking especially valuable.
How to Apply
- If you use a third-party docs platform (Mintlify, GitBook, ReadMe, Docusaurus hosting), verify that your custom domain isn't vulnerable to content injection via the platform's admin APIs.
- Apply strict CSP headers on your documentation domains — even if you don't control the underlying platform, you can limit what scripts can execute.
- For internal documentation sites: treat them with the same security rigor as your main product — they're often logged into by engineers with broad access.
- Audit your white-label SaaS vendors for the same class of vulnerability — any platform serving your domain is a potential XSS surface if their internal validation is weak.
Code Example
# CSP header example - applied to third-party proxy path
# nginx configuration
location /_mintlify/ {
add_header Content-Security-Policy "default-src 'none'; img-src 'self'; style-src 'self'; script-src 'none'; sandbox;";
proxy_pass https://upstream.mintlify.app;
}
# Block code generation from strings when running Node.js
node --disallow-code-generation-from-strings server.jsTerminology
Related Papers
Show HN: OpenKnowledge – open source AI-first alternative to Obsidian/Notion
Git 기반 동기화와 Claude/Codex/Cursor 연동을 내장한 로컬 우선 마크다운 에디터로, AI 에이전트의 두 번째 뇌(LLM Wiki)로 활용할 수 있는 오픈소스 도구다.
The Unfireable Safety Kernel: Execution-Time AI Alignment for AI Agents and Other Escapable AI Systems
AI 에이전트가 자신의 안전장치를 우회할 수 없도록, 에이전트 프로세스 바깥에 수학적으로 증명된 강제 통제 게이트를 배치하는 아키텍처
RubyLLM: A Ruby framework for all major AI providers
OpenAI, Claude, Gemini 등 주요 AI 프로바이더를 단일 인터페이스로 통합한 Ruby 프레임워크로, Rails 통합과 에이전트 기능까지 지원해 Ruby 개발자가 AI 기능을 빠르게 붙일 수 있다.
Qwen-AgentWorld: Language World Models for General Agents
Alibaba Qwen 팀이 AI 에이전트가 행동 결과를 미리 시뮬레이션할 수 있는 'Language World Model'을 공개했다. 에이전트 훈련과 실행 경로 검증에 새로운 패러다임을 제시하는 연구다.
SHERLOC: Structured Diagnostic Localization for Code Repair Agents
버그 위치만 알려주는 게 아니라 '왜, 어떻게 고쳐야 하는지'까지 진단 리포트를 생성해서 코드 수정 에이전트의 성능을 높이는 training-free 프레임워크
Show HN: peerd – AI agent harness that runs entirely in your browser
백엔드 서버 없이 Chrome/Firefox 확장 프로그램으로만 동작하는 AI 에이전트 실행 환경으로, 브라우저 탭을 직접 조작하고 WASM Linux VM까지 구동할 수 있어 프라이버시와 보안을 동시에 챙길 수 있다.