6.4

CVE-2025-67842

Exploit
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MintlifyMintlify Version < 2025-11-15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.231
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
cve@mitre.org 6.4 3.1 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Third Party Advisory
https://kibty.town/blog/mintlify/
Third Party Advisory
Exploit
https://news.ycombinator.com/item?id=46317098
Issue Tracking
https://www.mintlify.com/blog/working-with-security-researchers-november-2025
Vendor Advisory
https://www.mintlify.com/docs/changelog
Release Notes
https://heartbreak.ing
Third Party Advisory