CVE-2025-67845
MEDIUMDescription
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mintlify | mintlify |
References
Frequently Asked Questions
What is CVE-2025-67845? +
How severe is CVE-2025-67845? +
What products are affected by CVE-2025-67845? +
How do I check if I'm vulnerable to CVE-2025-67845? +
Related Vulnerabilities
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs …
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a path-traversal flaw in the …
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. …
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing …
The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller …