17 ms·
We pwned X, Vercel, Cursor, and Discord through a supply-chain attack
- normie3000 10mo agoCool bug. Bug bounty money is pathetic.
- FloorEgg 10mo agoSupply and demand I guess. Pathetic for a senior SE but pretty awesome for a 16 year old up and coming hacker.
- tuesdaynight 10mo agoYou are right, but that could (probably not) make them go for the bad route because they would get way more money that way. 4k for a bug that could take control of your customer account sounds disrespectful to me.
- finghin 10mo agoYeah, my read is that the teenage hacker confronted with this ridiculous payslip sees two ways forward: accept the pay cut for the CV benefit of working with bug bounties, or get a bit better at hiding your ass and make them really pay.
- james_marks 10mo agoIf I were 16, I’d be thinking I just made an obscene amount of money ($4,000!) messing with computers for fun, and got to meet people at a famous company. That’s a free car. Free computer. Uber eats for months. And my status with my peers as a hacker would be cemented. I get that bounty amounts are low vs SE salary, but that’s not at all how my 16yo self would see it.
- finghin 10mo agoWhen I was sixteen I was already familiar with the concept of leverage. I’m not sure if I’d have had the cajones to use it though.
- grenran 10mo agoPlaying devils advocate but 4k is probably more money than most kids that age have seen in their life
- finghin 10mo agoI hope I'm not assuming too much but I'm really hope the up and coming hacker is smart enough to know that his work was worth more than $4,000. That's 1-2% of an annual SE salary for someone with similar skillset.
- ascorbic 10mo agoAnd this will help them land that six figure job
- bbarn 10mo agoI mean, as a hiring manager, a fresh grad with multiple bug bounties tells me a lot about their drive and skill, so I'd agree. It's a great differentiator.
- MeetingsBrowser 10mo ago> That's 1-2% of an annual SE salary for someone with similar skillset. I agree $4,000 is way too low, but a $400k salary is really high, especially for security work.
- degamad 10mo ago> That's 1-2% of an annual SE salary for someone with similar skillset. So commensurate for approximately 2 days of work, a little high for two hours of work, and a little low for 8 days of work.
- yieldcrv 10mo agomarket value is the same regardless, so this was pathetic
- tuesdaynight 10mo agoWhat is the reason for the low values? I would understand if it was a small company, but we are talking about Discord here.
- charlesabarnes 10mo agoSupply and demand. Selling via grey markets is an option, but many white hats don't go that route due to risk. There's plenty of people that will also find vulnerabilities without any money attached.
- tptacek 10mo agoWhat "grey market" are you talking about? How specific can you be about it?
- jijijijij 10mo agoThat's a limited view. The damage this could cause should be accounted for. People don't have to sell shit, they could fuck things up just for the fun of it. That's something to consider, especially with a bunch of teenagers. Now, these big corpos didn't take the chance to sponsor and encourage these kids early careers and make this fuck-up good PR, at least.
- Aachen 10mo agoThat's not how economics works. I can't do my job without a computer or glasses but that doesn't mean I can pay the suppliers of these things most of my salary each. Preventing a 100k€ problem says almost nothing about what the payout should be. As for them just causing chaos for fun, that nets them just about nothing (what's an evening of fun worth, like what are you willing to pay for a cinema ticket?). This is certainly more (hundreds of times more) and so covers that risk as well
- bytecauldron 10mo agoI was going to ask. Isn't 4k from Discord pretty low for the work conducted here? I'm not familiar with bounty payouts. I'm hoping these companies aren't taking advantage of them.
- oxandonly 10mo ago4k is sadly discords highest bounty they give out (screenshot from their bugcrowd program: https://imgur.com/a/KNIdeXh https://imgur.com/a/KNIdeXh) even more critical issues then this one get paid the same amount out
- some_guy_nobel 10mo agoWhat do you expect? a16z-funded and they love to talk about how much they've raised, thought-leader style co-founders, etc.
- babelfish 10mo agoSounds like you pwned Mintlify!
- Aachen 10mo agoI critiqued the title elsewhere already so let me say here that the screenshot does show code running in Discord's browser context. They didn't send it to an employee and actually pwn the company, as one might understand from the title, but it doesn't strictly say that and I would count finding XSS as close enough. Saying they've pwned Discord, I think is fair enough The other three companies mentioned though... yeah, they totally pwned the dependency first and foremost
- padjo 10mo agoSeems like such a tiny amount of money for a bug that can be used to completely own your customers accounts. Also not much excuse for xss these days.
- da_grift_shift 10mo ago>Also not much excuse for xss these days. XSS is not dead, and the web platforms mitigations (setHTML, Trusted Types) are not a panacea. CSP helps but is often configured poorly. So, this kind of widespread XSS in a vulnerable third party component is indeed concerning. For another example, there have been two reflected XSS vulns found in Anubis this year, putting any website that deploys it and doesn't patch at risk of JS execution on their origin. Audit your third-party dependencies! https://github.com/TecharoHQ/anubis/security/advisories/GHSA-jhjj-2g64-px7c https://github.com/TecharoHQ/anubis/security/advisories/GHSA... https://github.com/TecharoHQ/anubis/security/advisories/GHSA-cf57-c578-7jvv https://github.com/TecharoHQ/anubis/security/advisories/GHSA...
- azemetre 10mo agoIs it really fair to compare an open source project that desperately wants only $60k a year to hire a dev with companies that have collectively raised over billions of dollars in funding?
- noirscape 10mo agoI'd say it's probably worse in terms of scope. The audience for some AI-powered documentation platform will ultimately be fairly small (mostly corporations). Anubis is promoting itself as a sort of Cloudflare-esque service to mitigate AI scraping. They also aren't just an open source project relying on gracious donations, there's a paid whitelabel version of the project. If anything, Anubis probably should be held to a higher standard, given many more vulnerable people (as in, vulnerable against having XSS on their site cause significant issues with having to fish their site out of spam filters and/or bandwidth exhaustion hitting their wallet) are reliant on it compared to big corporations. Same reason that a bug in some random GitHub project somewhere probably has an impact of near zero, but a critical security bug in nginx means that there's shit on the fan. When you write software that has a massive audience, you're going to have to be held to higher standards (if not legally, at least socially). Not that Anubis' handling of this seems to be bad or anything; both XSS attacks were mitigated, but "won't somebody think of the poor FOSS project" isn't really the right answer here.
- dllu 10mo agoThe fact that SVG files can contain scripts was a bit of a mistake. On one hand, the animations and entire interactive demos and even games in a single SVG are cool. But on the other hand, it opens up a serious can of worms of security vulnerabilities. As a result, SVG files are often banned from various image upload tools, they do not unfurl previews, and so on. If you upload an SVG to discord, it just shows the raw code; and don't even think about sharing an SVG image via Facebook Messenger, Wechat, Google Hangouts, or whatever. In 2025, raster formats remain way more accessible and easily shared than SVGs. This is very sad because SVGs often have way smaller file size, and obviously look much better at various scales. If only there was a widely used vector format that does not have any script support and can be easily shared.
- nightski 10mo agoDoes it need to be as complicated as a new format? Or would it be enough to not allow any scripting in the provided SVGs (or stripping it out). I can't imagine there are that many SVGs out there which take advantage of the feature.
- culi 10mo agoDo other vector formats have the same vulnerabilities?
- bobbylarrybobby 10mo agoWould it be possible for messenger apps to simply ignore <script> tags (and accept that this will break a small fraction of SVGs)? Or is that not a sufficient defense?
- demurgos 10mo agoI looked into it for work at some point as we wanted to support SVG uploads. Stripping <script> is not enough to have an inert file. Scripts can also be attached as attributes. If you want to prevent external resources it gets more complex. The only reliable solution would be an allowlist of safe elements and attributes, but it would quickly cause compat issues unless you spend time curating the rules. I did not find an existing lib doing it at the time, and it was too much effort to maintain it ourselves. The solution I ended up implementing was having a sandboxed Chromium instance and communicating with it through the dev tools to load the SVG and rasterize it. This allowed uploading SVG files, but it was then served as rasterized PNGs to other users.
- ddtaylor 10mo ago$11k in bounties. Might have got more from the onion.
- vablings 10mo agoStupid, especially because he is a kid and young in his career. His lifetime earnings and ability to score a better paying job is worth way more than an extra couple thousand dollars selling this kind of exploit to criminals. It's why NDA's for security vulnerabilities are harmful because it doesn't allow a kind of social credit accumulation
- azemetre 10mo agoBack in the day the US government would give you $20k-60k cash in a nice briefcase for this type of exploit. Just another thing big tech has ruined I suppose.
- tptacek 10mo agoCan you cite a source for that claim? The USG paying mid-5-figures for an XSS vulnerability? That's news to me.
- 0xbadcafebee 10mo agoI can't imagine intelligence agencies/DoD not doing this with their gargantuan black budgets, if it's relevant to a specific target. They already contract with private research centers to develop exploits, and it's not like they're gonna run short on cash
- tptacek 10mo agoIf that were the case, we'd routinely see mysterious XSS exploits on social networks. The underlying bugs are almost always difficult to target! And yet we do not. The biggest problem, again, is that the vulnerabilities disappear instantaneously when the vendors learn about them; in fact, they disappear in epsilon time once the vulnerabilities are used, which is not how e.g. a mobile browser drive-by works.
- bri3d 10mo agoProxying from the "hot" domain (with user credentials) to a third party service is always going to be an awful idea. Why not just CNAME Mintlify to dev-docs.discord.com or something? This is also why an `app.` or even better `tenant.` subdomain is always a good idea; it limits the blast radius of mistakes like this.
- pverheggen 10mo agoI think the reason companies do this for doc sites is so they can substitute your real credentials into code snippets with "YOUR_API_KEY". Seems like a poor tradeoff given the security downside.
- gkoberger 10mo agoI run a product similar to Mintlify. We've made different product decisions than them. We don't support this, nor do we request access to codebases for Git sync. Both are security issues waiting to happen, no matter how much customers want them. The reason people want it, though, is for SEO: whether it's true or outdated voodoo, almost everyone believes having their documentation on a subdomain hurts the parent domain. Google says it's not true, SEO experts say it is. I wish Mintlify the best here – it's stressful to let customers down like this.
- omneity 10mo agoTo my knowledge it's not as much hurting the parent domain as having two separate "worlds". Your docs which are likely to receive higher traffic will stop contributing any SEO juice to your main website.
- Dma54rhs 10mo agoWhat makes you say that Google claims it's not true? Google claims subdomains are completely two different domains and you'll lose all the linking/page rank stuff according to their own docs regarding SEO. Some SEO gurus claim it's not so black and white but no one knows for sure. The data does show having docs on subdomain is more harmful to your SEO if you get linked to then a lot.
- Illniyar 10mo agoNice discovery and writeup. Let alone for a 16 yo!. I've never heard an XSS vulnerability described as a supply-chain attack before though, usually that one is reserved for package managers malicious scripts or companies putting backdoors in hardware.
- bink 10mo agoI think that's misuse of the term as well, but like you said they are only 16.
- kenjackson 10mo agoI think you can view it as supply chain as the supply chain is about attacking resources used to infiltrate downstream (or is it upstream? I get which direction I should think this flows). As an end user you can't really mitigate this as the attack happens in the supply chain (Mintlify) and by the time it gets to you it is basically opaque. It's like getting a signed malicious binary. It looks good to you and the trust model (the browser's origin model) seems to indicate all is fine (like the signing on the binary). But because earlier in the supply chain they made a mistake, you are now at risk. Its basically moving an XSS up a level into the "supply chain".
- Aachen 10mo agoA supply chain attack attacks the supply chain This makes use of a vulnerability in a dependency. If they had recommended, suggested, or pushed this purposefully vulnerable code to the dependency, then waited for a downstream (such as Discord) to pull the update and run the vulnerable code, then they would have completed a supply chain attack The whole title is bait. Nobody would have heard of the dependency, so they don't even mention it, just call it "a supply chain" and drop four big other names that you have heard of to make it sexy. One of them was actually involved that I can tell from the post, that one is somewhat defensible. They might as well have written in the title that they've hacked the pentagon, if someone in there uses X and X had this vulnerable dependency, without X or the pentagon ever being contacted or involved or attacked
- 10mo ago
- dfedbeef 10mo agoJFC bug bounty money is pathetic now. This would have destroyed this company's reputation, downstream effects for customer reputations and data.
- llmslave2 10mo agoThis feels so emblematic of our current era. VC funded vibe coded AI documentation startup somehow gets big name customers who don't properly vet the security of the platform, ship a massive vulnerability that could pwn millions of users and the person who reports the vulnerability gets...$5k. If I recall last week Mintlify wrote a blog post showcasing their impressive(ly complicated) caching architecture. Pretending like they were doing real engineering, when it turns out nobody there seems to know what they're doing, but they've managed to convince some big names to use them. Man, it's like everything I hate about modern tech. Good job Eva for finding this one. Starting to think that every AI startup or company that is heavily using gen-ai for coding is probably extremely vulnerable to the simplest of attacks. Might be a way to make some extra spending money lol.
- tptacek 10mo agoI don't think anybody in SFBA-style software development, both pre- and post-LLM, is really resilient against these kinds of attacks. The problem isn't vibe coding so much as it is multiparty DLL-hell dependency stacks, which is something I attribute more to Javascript culture than to any recent advance in technology.
- llmslave2 10mo agoYou're right that it's a specific programming culture that is especially vulnerable to it. And for the same reasons they were vulnerable to the same thing to a lesser degree before the rise of LLMs. But like, this case isn't really a dependency or supply chain attack. It's just allowing remote code execution because, idk, the dev who implemented it didn't read the manual and see that MDX can execute arbitrary code or something. Or maybe they vibe coded it and saw it worked and didn't bother to check. Perhaps it's a supply-chain attack on Discord et al to use Mintlify, if thats what you meant then I apologize. I think you're right that I have an extreme aversion to SFBA-style software development, and partly because of how gen-ai is used there.
- michaelt 10mo agoOne might consider this a supply chain attack because the title of the post is “We pwned X, Vercel, Cursor, and Discord through a supply-chain attack”
- bluetidepro 10mo agoSlightly related, as someone who doesn’t engage in this type of work, I’m curious about the potential risks associated with discovering, testing, and searching for security bugs. While it’s undoubtedly positive that this individual ultimately became a responsible person and disclosed the information, what if they hadn’t? Furthermore, on Discord’s side, what if they were unaware of this person and encountered someone attempting to snoop on this information, mistakenly believing them to be up to no good? Has there been cases where the risk involved wasn’t justified by the relatively low $4k reward? Or any specific companies you wouldn’t want to do this with because of a past incident with them?
- pverheggen 10mo ago> Furthermore, on Discord’s side, what if they were unaware of this person and encountered someone attempting to snoop on this information, mistakenly believing them to be up to no good? Companies will create bug bounty programs where they set ground rules (like no social engineering), and have guides on how to identify yourself as an ethical hacker, for example: https://discord.com/security https://discord.com/security
- jijijijij 10mo agoThere are laws governing these scenarios. It's different everywhere. Portugal just updated theirs in favor of security researchers: https://www.bleepingcomputer.com/news/security/portugal-updates-cybercrime-law-to-exempt-security-researchers/ https://www.bleepingcomputer.com/news/security/portugal-upda...
- michaelt 10mo agoIf you engage in “white hat security research” on organisations who haven’t agreed to it (such as by offering roles of engagement on a site like hacker one) there is indeed a risk. For example they might send the police to your door, who’ll tell you you’ve violated some 1980s computer security law. I know 99.99% of cybercrime goes unpunished, but that’s because the attackers are hard to identify, and in distant foreign lands. As a white hat you’re identifiable and maybe in the same country, meaning it’s much easier to prosecute you.
- lrvick 10mo agoI run an infosec firm and we have done attacks like this on my clients over and over and over in audits. I always say any bored teen could do most of what we do because most companies are moving too fast feature farming to have any time for responsible security hardening, and now I have yet another great citation. Unfortunately a competitive rate agreed to in advance with a company before we do any pentesting is the only way we have ever been able to get paid fairly for this sort of work. Finding bugs in the wild as this researcher did often gets wildly underpaid relative to the potential impact of the bug, if they pay or take it seriously at all. These companies should be ashamed paying out so little for this, and it is only a matter of time before they insult the wrong researcher who decides to pursue paths to maximum profit, or maximum damage, with a vuln like this.
- jijijijij 10mo ago> Unfortunately a competitive rate agreed to in advance with a company before we do any pentesting is the only way we have ever been able to get paid fairly for this sort of work. So, rough estimate, how much would you have made for this?
- lrvick 10mo agoWe normally find things like this in our usual 60 hour audit blocks. Rates change over time with demand, but today an audit of that length would be $27k. Even that is quite cheap compared to letting a blackhat find this.
- lowkey_ 10mo agoIf I can ask on business model, as I have a friend with a similar predicament — what percent of the time do you find vulnerabilities in those audits? Do companies push back if you don't find vulnerabilities?
- rainonmoon 10mo agoAs someone in a related line of work: we find vulnerabilities so close to 100% of the time that it might as well be 100% of the time. Whether they're practically exploitable or surpass your risk appetite is the real question.
- JackSlateur 10mo agoI struggle to understand the issue .. could someone help me out ? Ok, you got "https://discord.com/_mintlify/_static/hackerone-a00f3c6c/lmao.svg https://discord.com/_mintlify/_static/hackerone-a00f3c6c/lma..." to send a controlled payload But regular users will never hit "https://discord.com/_mintlify/_static/hackerone-a00f3c6c/lmao.svg https://discord.com/_mintlify/_static/hackerone-a00f3c6c/lma...", so they will never execute your script I fail to understand how this can be exploited, by whom and in what conditions
- rainonmoon 10mo agoYou're pretty much on the money. Reflected XSS requires social engineering to really target anyone without other primitives. Unfortunately this report is not very clear about the tangible impacts or limitations of what they could do with this particular XSS either. Saying that every Mintlify customer was "vulnerable to account takeover with a single malicious link" strikes me as specious to say the least. Still, can't fault kids for getting excited about recognition and a payout.
- hackermondev 10mo agoimo, the impact is pretty clear here. an unsuspecting user clicks (or is redirected) to one of these malicious links on the platform (ex. vercel); the script grabs their cookie and credentials and sends it to the attacker. they now have full access to the victim's account.
- rainonmoon 10mo agoNice! So the Cookie is accessible by JavaScript on all of those sites? That would be pretty surprising given the prevalence of HttpOnly, so that doesn't seem clear to me at all. And they're all using Cookie-based auth, you think? You're a bug bounty hunter so I'll defer to your wisdom, but doesn't it seem more likely that an account takeover would be possible via a state-changing request from the user's existing session? Let's say they can abuse it to reset the user's password. Nice, that's an account takeover... for every user not using MFA. But then there are anti-CSRF mitigations. Okay, not insurmountable with an XSS, but implemented differently everywhere. And what if the auth domains are separate to the domain on which the XSS is triggered? Man this seems to get less clear by the minute. Please clear this up for me.
- 0xbadcafebee 10mo agoHow these companies don't hire kids like Daniel for pennies on the dollar and have him attack their stacks on a loop baffles me. Pay the kid $50k/yr (part time, he still needs to go to school) to constantly probe your crappy stacks. Within a year or two you'll have the most goddamn secure company on the internet - and no public vulns to embarrass you.
- zwnow 10mo agoWhile I would love that for the kid I dont think these companies care about security at all.
- bink 10mo agoIt's not quite that simple. I don't think most bug bounty participants want a full-time job. But even more-so in my experience they are not security generalists. You can hire one person who is good at finding obscure XSS vulns, another that's good at exploiting cloud privilege escalation in IAM role definitions, another that's good at shell or archive exploits. If you look at profiles on H1 you'll see most good hackers specialize in specific types of findings.
- wiether 10mo agoThat's a bit simplistic. If you sign a contract with a "hacker", then you are expecting results. Otherwise how do you decide to renew the contract next year? How do you decide to raise it next year? What if, during this contract, a vulnerability that this individual didn't found is exploited? You get rid of them? So you're putting pressure on a person who is a researcher, not a producer. Which is wrong. And also there's the scale. Sure, here you have one guy who exploited a vulnerability. But how long it took them to get there? There's probably dozens of vulnerabilities yet to be exploited, requiring skills that differ so much from the ones used by this person that they won't find them. Even if you pay them for a full-time position. Whereas, if you set up a bug bounty program, you are basically crowdsourcing your vulnerabilities: not only you probably have thousands of people actively trying to exploit vulnerabilities in your system, but also, you only give money to the ones that do manage to exploit one. You're only paying on result. Obviously, if the reward is not big enough, they could be tempted to sell them to someone else or use them themselves. But the risk is here no matter how you decide to handle this topic.
- YouAreWRONGtoo 10mo ago[dead]
- hinkley 10mo agoIt’s clear to me now that I need to set up my home machine the way I set up BYOD when I was contracting last. I need a separate account for all of my development. I have a friend who at one point had five monitors and 2 computers (actually it might be 3) on his desk and maybe he’s the one doing it right. He keeps his personal stuff and his programming/work stuff completely separate.
- combyn8tor 10mo agoI have three OS installs. Windows install for games. Another Windows for development (I have to for windows dev). And a Ubuntu install for anything not games/work. The windows drives use bitlocker and they can't access each other's files. It's not perfect. Although with the amount of crap I have to install for windows development I'm starting to wonder if a base VM image that is used as a start point for each project would be cleaner.
- myaccountonhn 10mo agoI set up a separate user that I ssh into for development. Not perfect but its something.
- multisport 10mo agodecided to make a new account to post: Mintlify security is the worse I have even encountered in a modern SaaS company. They will leak your data, code, assets, etc. They will know they did this. You will tell them, they will acknowledge that they knew it happened, and didn't tell you. Your docs site will go down, and you will need to page their engineers to tell them its down. This will be a surprise to them.
- arpinum 10mo agoYes, they were sloppy with GitHub credentials and their response was inadequate. Glad we migrated away from them.
- fazkan 10mo agowhere did you migrate away to?
- hunvreus 10mo agoAbsolute self-promotion: https://github.com/hunvreus/reallysimpledocs https://github.com/hunvreus/reallysimpledocs
- promiseofbeans 10mo agoAstro’s starlight docs generator/template is quite nice as well: https://starlight.astro.build/ https://starlight.astro.build/
- throwaway613745 10mo agoOk, I’m never opening an svg ever again. Found by a 16 year old, what a legend.
- prmoustache 10mo agoOpen it with a browser running inside a jail.
- ex-aws-dude 10mo agoI tried that and they wouldn't let me bring my laptop in
- prmoustache 10mo agohttps://man.freebsd.org/cgi/man.cgi?jail https://man.freebsd.org/cgi/man.cgi?jail https://github.com/Zouuup/landrun https://github.com/Zouuup/landrun
- gavinray 10mo agoAlright, I chuckled.
- orliesaurus 10mo agoI've been following the rise of SVG based attacks recently... It's not just hypothetical anymore... People are using SVG files to deliver full phishing pages and drive by downloads by hiding JavaScript in the markup ALSO as someone who maintains a file upload pipeline I run every SVG through a sanitizer... Tools like DOMPurify remove scripts and enforce a safe subset of the spec... I even go as far as rasterizing user uploaded vectors to PNG when possible HOWEVER the bigger issue is mental... Most folks treat SVG like a dumb image when browsers treat it like executable content... Until the platform changes that expectation there will always be an attack surface
- quasarj 10mo agoOne of these days I'm gonna have to learn why cross-site scripting even matters, especially with modern browsers restricting a script's access to anything local
- LocalPCGuy 10mo agoIf I can run my own code but in your context, I can pull in malicious scripts. With those (all these are "possible" but not always, as usual, it depends, and random off the top of my head): - I can redirect you to sites I control where I may be able to capture your login credentials. - May be able to prompt and get you to download malware or virus payloads and run them locally. - Can deface the site you are on, either leading to reputational harm for that brand, or leading you to think you're doing one thing when you're actually doing another. - I may be able to exfiltrate your cookies and auth tokens for that site and potentially act as you. - I might be able to pivot to other connected sites that use that site's authentication. - I can prompt, as the site, for escalated access, and you may grant it because you trust that site, thereby potentially gaining access to your machine (it's not that the browsers fully restrict local access, they just require permission). - Other social engineering attacks, trying to trick you into doing something that grants me more access, information, etc.
- gowld 10mo agoYou log in to goodsite.com goodsite.com loads a script from user-generated-content-size.com/evil.js evil.js reads and writes all your goodsite.com account data.
- Sohcahtoa82 10mo agoThe attacker can do anything using your session. The "Hello world" examples always show using it to steal your cookies, which obviously doesn't work now when nearly every site uses the "httpOnly" flag which makes the cookie inaccessible to JavaScript, but really, stealing your session isn't necessary. They just have to make the XSS payload run the necessary JavaScript. Once the JavaScript is running on the page, all bets are off. They can do ANYTHING that the page can do, because now they can make HTTP requests on your behalf. SOP no longer applies. CSRF no longer protects you. The attacker has full control of your account, and all the requests will appear to come from YOUR browser.
- dfbrown 10mo agoTheir collaborator's report includes a more significant issue, an RCE on a mintlify server: https://kibty.town/blog/mintlify/ https://kibty.town/blog/mintlify/
- gowld 10mo agoThe linked site https://heartbreak.ing/ https://heartbreak.ing/ explains that Mintlify disabled CORS, so that 3rd party sites can run code in your Mintlify-using environment (X, Vercel, etc). The OP site says that .svg files can only run scripts if they are directly opened, not via <img> tags. So how does the attack work?
- LocalPCGuy 10mo agoMy understanding, the SVGs were imported directly and embedded as code, not as a `src` for an img tag. This is very common, it's a subjectively better (albeit with good security practices) way to render SVGs as it provides the ability to adjust and style them via CSS as they are now just another element in the HTML DOM. It should only be done with "trusted" SVGs however! As for CORS, they were uploading the SVGs to an account of their own, but then using the vulnerabilities to pivot to other accounts.
- gowld 10mo agoThanks, that makes sense. Strange that the writeup skipped the most important step in the vulnerability!
- mihaaly 10mo agoMove fast and break things? I have this feeling with almost all web tools I am required to use nowadays. No trust.
- ozozozd 10mo agoMove fast and break _other people's things._
- skrebbel 10mo agoat this point I feel like it'd be useful for web server default configurations to include something like if extension == .svg set-header Content-Security-Policy: script-src 'none' end wouldn't that stop a browser from running scripts, even if the svg file is opened directly? having this be widespread would solve it wholesale.
- vpShane 10mo agoNot a bad idea!
- whimsicalism 10mo agofascinating! but this is not a supply-chain attack unless i'm misunderstanding
- td2 10mo agoIt kinda is no? Discord uses mintlyfly. Minitlifly was vulnerable. And because they got access to mintlifly, discord was now also attackable
- whimsicalism 10mo agothat’s just a vulnerability in a dependency. a supply-chain attack is introducing malicious code in a dependency
- Aachen 10mo agoThat's how language shifts. Supply chain attacks are broadly seen as a scary new thing, so like with any such term, people try to shoehorn things they find into its meaning. Those who fall for and repeat it shift the language. The same happened to the word 0day: it used to mean "a vulnerability that you specifically haven't had a chance to patch because it has been known to the world for 0 days". A scary thing. Now it's commonly used as synonym for the word vulnerability I wonder if every vulnerability is soon called a supply chain attack: - Microsoft releases a Windows security update -> Discord uses Windows -> supply chain attack on Discord - User didn't install security updates for a while -> brought their phone to work -> phone with microphone sits in pocket in meeting room -> supply chain attack Everything has dependencies that can be vulnerable, that doesn't mean "the supply chain" was attacked in a targeted effort by some attacker
- marisen 10mo agoGiven this (including the linked writeup on the mintlify RCE), after the React RCE, if think it should be pretty obvious that 1. content security policies should always be used to prevent such scripts (here they would prevent execution of scripts from the SVG) 2. The JavaScript ecosystem should be making ` --disallow-code-generation-from-strings` a default recommendation when running NodeJS on the server. Vercel (and other nodejs as a service providers) should warn customers that don't use CSP and `--disallow-code-generation-from-strings` that their settings should be improved. There are a bunch of other NodeJS flags that maybe you should look into too: https://sgued.fr/blog/react-rce/#node-js-mitigations https://sgued.fr/blog/react-rce/#node-js-mitigations
- superasn 10mo agoThis is a pretty scary exploit, considering how easily it could be abused. Imagine just one link in a tweet, support ticket, or email: https://discord.com/_mintlify/static/evil/exploit.svg https://discord.com/_mintlify/static/evil/exploit.svg. If you click it, JavaScript runs on the discord.com origin. Here's what could happen: - Your Discord session cookies and token could be stolen, leading to a complete account takeover. - read/write your developer applications & webhooks, allowing them to add or modify bots, reset secrets, and push malicious updates to millions. - access any Discord API endpoint as you, meaning they could join or delete servers, DM friends, or even buy Nitro with your saved payment info. - maybe even harvest OAuth tokens from sites that use "Login with Disord." Given the potential damage, the $4,000 bounty feels like a slap in the face. edit: just noticed how HN just turned this into a clickable link - this makes it even scarier!
- snvzz 10mo ago>the $4,000 bounty feels like a slap in the face. And serves a reminder crime does pay. In the black market, it would have been worth a bit more.
- tptacek 10mo agoNo it would not have been.
- tuhgdetzhh 10mo agoCould you elaborate on why not?
- arcwhite 10mo agoThere's generally no grey market for XSS vulns. The people buying operationalized exploits generally want things that they can aim very specifically to achieve an outcome against a particular target, without that target knowing about it, and operationalized XSS vulns seldom have that nature. Your other potential buyers are malware distributors and scammers, who usually want a vuln that has some staying power (e.g. years of exploitability). This one is pretty clearly time-limited once it becomes apparent.
- kizer 10mo agoCool. Makes me want to get into that — checking out sites for vulnerabilities. Very impressive for a 16 year old. Should definitely have been paid more.
- ta1999 10mo agoNot shocked given the following statement from Mintlify to a recruiter a few months ago: "I'd rather hire a junior dev who knows the latest version of NextJS than a senior dev who is experienced with an earlier version." This would be a forgivable remark, except the recruiter was aware of the shortsightedness, and likely attempted to coach the hiring manager...
- Defletter 10mo agoOkay, seriously, can we just get one, just ONE document/image spec that doesn't let you embed scripts or remote content? What is with this constant need to put the same exactly vulnerability into EVERYTHING?! Just let me have a spec for completely static documents, jfc!
- hunvreus 10mo agoMintlify does look pretty, but between that and all the React exploits, I'll stick with good ol' static sites. Kinda why I built ReallySimpleDocs [1]. Add Pages CMS [2] to it and you're set. [1]: https://reallysimpledocs.com/ https://reallysimpledocs.com/ [2]: https://pagescms.org https://pagescms.org
- est 10mo agocould `Sec-Fetch-Dest: image` mitigate this?
- geekamongus 10mo ago16 year olds rule the world.
- deleted 10mo ago[deleted]
- varenc 10mo agoThis is a great example of why a Content-Security-Policy (CSP Header) should be considered mandatory for high risk sites. With it you can effectively tell the browser what JS is allowed to run, meaning that any JS injected via XSS won't work. I suspect Coinbase and others already use CSP. https://en.wikipedia.org/wiki/Content_Security_Policy https://en.wikipedia.org/wiki/Content_Security_Policy
- Aeolun 10mo agoDamn, this is a good era to be in high school (or university) with a lot of free time. $4000 is a pretty good haul for a few hours of work poking at stuff.
- greesil 10mo agoEverything is Swiss cheese. Let's just go back to paper and pen and one time pads.
- trollbridge 10mo agoA lesson from this is that you shouldn't host third-party stuff in your own domain. Instead of placing it on docs.discord.com, place it on discord-docs.com.
- enescakir 10mo agoThey have more security incidents than you'd expect for a documentation company. There was another one just last month.
- gatestone 10mo agoWho ever invented the idea that you can embed Javasript to picture files?
- voodooEntity 10mo agoReally nice finding for such a young folk - really liked reading into it.Also what i love most about it is what an actually simple vuln it is. Tho what i find mostly funny bout it is how many people are complaining about the 4k$. I mean sure the potential "damage" could have been alot higher, tho at the same time there was no contract in place or , at least as far as i understood, a clear bug bounty targeted. This was a, even if well done, random checking of XHR/Requests to see if anything vulnerable can be found - searching for kinda file exposure / xss / RFI/LFI. So everything paid (and especially since this is a mintlify bug not an actual discord bug) is just a nice net gain. Also ill just drop here : ask yourself, are you searching for such vulns just for money or to make the net a safer place for everyone. Sure getting some bucks for the work is nice, but i personally just hope stuff gets fixed on report.
- isodev 10mo agoBtw, apart from Discord, you really should stop using the other ones (X, Vercel, Cursor...). Do yourself and the planet a favour :)
- promiseofbeans 10mo agoStop using Discord as well - their software is packed full of data mining, ads, and cosmetic upsells. For public community groups use a forum site (then it’s indexable as well!), and for private groups use something actually private like Signal
- matt3210 10mo ago>AI-powered documentation platform. You write your documentation as markdown and Mintlify turns it into a beautiful documentation platform Why do you need AI for this? Aren't there tons of packages which do very similar things without AI?
- codedokode 10mo agoIt is clear that SVG should not support scripts and CSS in SVG files. Those who need them can simply create HTML with inline SVG tags and scripts. And SVG should contain only shapes, effects and transformations. Or maybe we need a new image format, "SVG without scripts and CSS".
- DoctorOW 10mo agoCSS and scripts are wildly different. It's like responding to the old MS Office attacks with "Word without macros or font selection"
- codedokode 10mo agoThe problem with CSS is that if you want to write an SVG viewer, you have to implement a whole CSS engine, which might be more complex than SVG renderer itself. And if you create an image in an editor, like Inkscape, you don't use CSS anyway. CSS is meant to be used when you write the code manually (instead of using an editor), for example, in a web app, and in this case you could use HTML as well. So yes, CSS is not needed.
- rldjbpin 10mo agothis was very well-written and the moving parts were quite easy to understand. simultaneously there are many opportunities throughout to harden one's app to avoid similar exploits.
- kringle 10mo ago- enormously awesome - that bug bounty was insufficient (Fidelity?!?!)
- davidfstr 10mo ago> If you didn't know, you can embed JavaScript into an SVG file. Oh yikes. I did not know.
- vittore 10mo agoLink here is to gist , but on lobste.rs some one posted link to Eva's blog. And it with links to friends blogs, feel so much like old internet. I dont even know what I enjoyed more, reading technical side or discovering this dark forest.
- bigthroat 10mo agoInteresting timing — we captured downstream exploitation of this exact attack surface. 38 days after @hackermondev's disclosure, our automated OSINT harvester pulled 121 IOCs from OpenPhish/OTX: - 101 URLs for discord.flawing.top/blog/* (mimicking Discord's documentation structure) - 20 URLs for openopenbox301.vercel.app (phishing hosted ON Vercel) The attackers read the same disclosures we do. They just build infrastructure instead of writing reports. Evidence (queryable): curl "https://analytics.dugganusa.com/api/v1/search?q=discord.flawing.top" Full writeup with IOCs: https://www.dugganusa.com/post/mintlify-xss-downstream-exploitation-captured STIX feed (free): https://analytics.dugganusa.com/api/v1/stix-feed
- blindriver 10mo agoevery commit in every open source project should now go through an AI to see if it can detect anything nefarious. I'm sure there are ways to fool it but it makes it a lot easier for bad actors to get caught.
- wbnns 10mo agoThe collected bounty on this should have been so much higher than $14K :/
- franga2000 9mo agoI really don't get the appeal to have everything om one top-level domain, especially completely separate or even external services. The scope of this would've been basically zero if they just put it on docs.discord.com. Especially something like this, where they were reverse proxying a SaaS, seems extra stupid. It's more work to set up, adds an unnecessary dependency between services and you end up paying for all the internet traffic three times (even if not directly).
- deleted 9mo ago[deleted]
- anderson466 9mo ago[dead]