We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
TL;DR Highlight
Mintlify's AI docs platform had an internal endpoint validation gap that allowed injecting malicious JavaScript into customer domains like discord.com and docs.x.com.
Who Should Read
Security engineers reviewing SaaS platforms with white-label or custom domain features, and frontend security practitioners.
Core Mechanics
- Mintlify hosts documentation for major tech companies (Discord, X, etc.) and allows custom domains — the vulnerability let an attacker inject arbitrary JavaScript into those customer-owned domains.
- The root cause was insufficient validation of internal API endpoints that were accessible with lower privilege levels, allowing content injection that bypassed CSP for affected domains.
- The injected scripts could steal session tokens, perform phishing, or exfiltrate data from users of the affected documentation sites.
- The scope was significant: any visitor to the affected documentation pages (including enterprise customers' internal docs) could have been targeted.
- Mintlify patched the issue after responsible disclosure, but the exploit window is unknown.
Evidence
- The researcher provided a working proof-of-concept showing malicious JS executing on docs.x.com and discord.com domains.
- HN commenters noted this is a common class of vulnerability in white-label SaaS — the aggregation risk of one platform serving many high-value domains.
- Concern was raised about supply chain implications: documentation sites often load third-party analytics, fonts, and chat widgets — an XSS here could pivot to those.
- Several security engineers noted the specific risk of doc site XSS: developers are often logged in to internal tools while reading docs, making session hijacking especially valuable.
How to Apply
- If you use a third-party docs platform (Mintlify, GitBook, ReadMe, Docusaurus hosting), verify that your custom domain isn't vulnerable to content injection via the platform's admin APIs.
- Apply strict CSP headers on your documentation domains — even if you don't control the underlying platform, you can limit what scripts can execute.
- For internal documentation sites: treat them with the same security rigor as your main product — they're often logged into by engineers with broad access.
- Audit your white-label SaaS vendors for the same class of vulnerability — any platform serving your domain is a potential XSS surface if their internal validation is weak.
Code Example
# CSP header example - applied to third-party proxy path
# nginx configuration
location /_mintlify/ {
add_header Content-Security-Policy "default-src 'none'; img-src 'self'; style-src 'self'; script-src 'none'; sandbox;";
proxy_pass https://upstream.mintlify.app;
}
# Block code generation from strings when running Node.js
node --disallow-code-generation-from-strings server.jsTerminology
Related Papers
Migrating a production AI agent to GPT-5.6: 2.2x faster, 27% cheaper
마케팅 웹사이트를 자동 생성하는 프로덕션 AI 에이전트를 Claude Opus 4.8에서 GPT-5.6 Sol로 전환한 실전 경험담으로, 단순 모델 교체가 아니라 eval 하네스, 툴 스키마, 캐싱, 추론 리플레이까지 손봐야 했던 과정을 구체적인 수치와 함께 정리했다.
What xAI's Grok build CLI sends to xAI: A wire-level analysis
xAI의 공식 코딩 CLI 도구 Grok Build가 사용자 동의 없이 전체 Git 저장소와 .env 시크릿 파일을 xAI 서버로 업로드한다는 사실이 네트워크 트래픽 분석으로 밝혀졌다.
Remember When It Matters: Proactive Memory Agent for Long-Horizon Agents
LLM 에이전트가 긴 작업 중 중요한 정보를 잊어버리는 문제를 별도의 메모리 에이전트가 '적절한 타이밍에' 끼어들어 해결하는 방법
WebSwarm: Recursive Multi-Agent Orchestration for Deep-and-Wide Web Search
복잡한 웹 검색을 재귀적으로 분해하고 각 노드에 적합한 검색 모드를 동적으로 할당하는 멀티에이전트 프레임워크
Show HN: Reverse-engineering web apps into agent tools
로그인된 웹 앱의 API 호출을 브라우저에서 감시해 자동으로 MCP 도구로 변환하는 에이전트를 만들었다. 소스 코드나 공식 API 문서 없이도 Jira, Spotify 같은 서비스에 AI 어시스턴트를 붙일 수 있다.
Show HN: FableCut – A browser video editor AI agents can drive (zero deps)
타임라인 전체를 JSON 파일 하나로 표현하고 MCP/REST로 AI 에이전트가 직접 편집할 수 있는 브라우저 비디오 에디터로, Claude 같은 AI가 프롬프트 하나로 영상을 자동 컷편집하고 결과를 실시간으로 UI에 반영해준다.