Writer AI Patches Critical Cross-Tenant Flaw That Exposed Customer Sessions

A one-click bug dubbed WriteOut let outsiders hop between customer accounts on the enterprise AI platform before it was quietly fixed.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a modern glass office corridor at dusk
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers at Sand Security disclosed a critical session isolation flaw in Writer, an enterprise AI platform, in 2025.
  • The bug, nicknamed WriteOut, could let an outsider take over any Writer account with a single click by the victim.
  • Writer has patched the vulnerability, and no customer action is currently required beyond standard account hygiene.
  • The flaw sat in Writer's agent preview feature, which leaked session tokens across customer tenants that should have been walled off from each other.

Writer, an enterprise generative AI platform that companies use to build custom writing agents, has fixed a critical vulnerability that broke the wall between paying customers.

The flaw was found by researchers at Sand Security, who named it WriteOut. It was first reported by The Hacker News. An attacker with no prior access could have taken over another company's Writer account if a single user clicked one crafted link.

What actually went wrong inside Writer?

The bug lived in Writer's agent preview feature, the tool that lets developers try out an AI agent before publishing it. Previews were supposed to run inside a customer's own private space, known in cloud jargon as a tenant. They didn't.

The preview flow leaked session tokens, the digital keys that prove a user is logged in, across those tenant boundaries. An attacker who lured a Writer user into loading a malicious preview could scoop up that token and impersonate them, reading anything the victim could read: prompts, uploaded files, and any connected data sources wired into the target company's Writer agents.

Sand Security called it a one-click attack. The victim didn't need to enter credentials or approve anything. A click was enough.

Who was exposed?

Writer markets itself to large enterprises that feed sensitive internal text into its agents. A cross-tenant flaw in that setting is serious because one customer's data is meant to be invisible to every other customer sharing the platform.

Writer patched the issue after private disclosure. There's no public evidence that WriteOut was exploited before the fix landed.

Writer hasn't published a detailed public advisory. That matters. Enterprise AI vendors sit outside the CVE numbering system that covers most software flaws, which means customers often learn about serious bugs through researcher blogs rather than vendor bulletins. Our coverage of MCP's enterprise overhaul on 26 June flagged exactly this gap: when vendors offload security accountability, customers lose visibility into what's been broken and when it was fixed.

Should you worry?

If your organisation uses Writer, a few steps are worth taking. Rotate any API keys tied to Writer agents. Check audit logs for unusual preview activity or logins from unfamiliar locations. Ask your Writer account team, in writing, for the date the patch deployed and whether your tenant showed any indicators of prior abuse.

For staff who simply use Writer to draft copy: nothing to do. The fix is server-side.

Why this keeps happening to AI platforms

WriteOut fits a pattern researchers have been flagging all year. Agent-building features ship fast; the access controls that keep customers separate get less attention. Session tokens must be scoped tightly. Preview environments must inherit the same isolation rules as production. When one customer's browser can touch another customer's session, even briefly, the model has failed.

It's the same class of problem we reported on 3 July with ConsentFix, which turned Microsoft sign-in prompts into session-theft machinery. The mechanics differ; the underlying failure, weak token scoping in a feature that moves fast, is nearly identical.

Watch whether Writer publishes a formal advisory with a patch date. If it doesn't, that's your answer about how much this vendor treats security disclosure as a customer obligation rather than a PR choice.

© 2026 Threat Vectr