PT-2025-52403 · Mintlify · Mintlify Platform

Hackermon

+1

·

Published

2025-12-18

·

Updated

2025-12-19

·

CVE-2025-67842

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mintlify Platform versions prior to 2025-11-15
Description The Static Asset API in Mintlify Platform is susceptible to a cross-tenant asset injection issue. This allows remote attackers to inject arbitrary web script or HTML through manipulation of the subdomain parameter. Specifically, assets belonging to one tenant can be served on another tenant's documentation site.
Recommendations Update Mintlify Platform to version 2025-11-15 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67842

Affected Products

Mintlify Platform