6.4

CVE-2025-67845

Exploit
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MintlifyMintlify Version < 2025-11-15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.384
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
cve@mitre.org 6.4 3.1 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CWE-24 Path Traversal: '../filedir'

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

https://kibty.town/blog/mintlify/
Third Party Advisory
Exploit
https://news.ycombinator.com/item?id=46317098
Issue Tracking
https://www.mintlify.com/blog/working-with-security-researchers-november-2025
Vendor Advisory
https://www.mintlify.com/docs/changelog
Release Notes
https://heartbreak.ing/
Third Party Advisory