Supply chain β›“ Supply Chain

TechCrunch

πŸ“… 2024-03-01 🏒 Mintlify documentation platform
Primary Source β†—

Incident Details

Mintlify, an AI-powered code documentation platform used by software developers, suffered a breach on March 1, 2024. A vulnerability in Mintlify’s systems allowed unauthorized access to admin tokens, leading to the exposure of 91 GitHub OAuth tokens belonging to customer organizations. Attackers confirmed access to at least one customer repository. Because Mintlify requires read/write access to GitHub repositories to generate documentation, the supply chain risk was significant β€” downstream customer source code repositories could have been read or modified. Mintlify revoked all tokens immediately, patched the vulnerability, and moved away from storing GitHub OAuth tokens in databases. The incident underscored the risk of third-party developer tools that require broad repository access.

Technical Details

Initial Attack Vector
CWE-312: Cleartext Storage of Sensitive Information (OAuth tokens stored in database)
Vendor / Product
Mintlify documentation platform
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-03-01 Breach occurred
  2. 2024-03-18 Publicly disclosed
  3. 2024-03-18 Customers notified