CVE-2025-67842
CVE-2025-67842
6.4
MediumPublished:
Last updated:
Source:cve@mitre.org
Analyzed
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Changed
- Confidentiality
- Low
- Integrity
- Low
- Availability
- None
Description
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
References
cve@mitre.org
https://heartbreak.ingcve@mitre.org
https://kibty.town/blog/mintlify/cve@mitre.org
https://news.ycombinator.com/item?id=46317098cve@mitre.org
https://www.mintlify.com/docs/changelog134c704f-9b21-4f2e-91b3-4a467353bcc0
https://kibty.town/blog/mintlify/