CVE-2025-67842
MEDIUMMintlify Platform <2025-11-15 - XSS
Title source: llmDescription
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
References (6)
Scores
CVSS v3
6.4
EPSS
0.0008
EPSS Percentile
23.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Classification
CWE
CWE-829
Status
published
Affected Products (1)
mintlify/mintlify
< 2025-11-15
Timeline
Published
Dec 19, 2025
Tracked Since
Feb 18, 2026