WriteOut Flaw Enabled Writer AI Cross-Tenant Session Hijack

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Sand Security Research disclosed a critical session isolation vulnerability codenamed WriteOut in Writer's enterprise generative AI platform that enabled cross-tenant compromise
- The one-click flaw let an outsider with no prior access take over any Writer AI organization by tricking a logged-in victim into clicking a malicious agent preview link shared from an attacker's own account
- Attackers exploited Writer's AI managed sandbox and live preview feature to capture session cookies from completely separate companies and act inside each as a real user, breaking tenant isolation
- Successful exploitation could expose private chats, documents, agent configurations, private models, connectors, and LLM credentials, with potential administrative control depending on the victim's role
- Writer patched the flaw by preventing session cookies from being forwarded into sandbox previews and moving them to an isolated origin following responsible disclosure
- Sand Security bypassed Writer's input-side guardrails by instructing the agent to fetch and run a remote script — since the filters examined prompt instructions rather than runtime behavior, the actual exploit logic never appeared in the prompt
Why it matters: Enterprise AI platforms hosting agents for multiple organizations assume tenant isolation protects sensitive data — WriteOut shows that a single preview link from an outsider can shatter that assumption, granting access to private models, LLM credentials, and admin controls inside industry-leading enterprises using Writer.




