CVE-2025-67842
MEDIUMDescription
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mintlify | mintlify |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-67842? +
How severe is CVE-2025-67842? +
What products are affected by CVE-2025-67842? +
How do I check if I'm vulnerable to CVE-2025-67842? +
Related Vulnerabilities
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level control …
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. …
pip prior to version 26.1 would run self-update check functionality after installing wheel files which required importing well-known Python modules …
A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handling of untrusted input …
A critical security vulnerability exists in remote cache extensions for common build systems utilizing bucket-based remote cache (such as those …
conda-forge-metadata provides programatic access to conda-forge's metadata. conda-forge-metadata uses an optional dependency - "conda-oci-mirror" which was neither present on the …