Aller au contenu

Fiche vulnérabilité

CVE-2025-67842 : faille moyenne mintlify mintlify (CVSS 5.4)

Description

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
19 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • mintlify mintlify

Références

Rechercher une autre vulnérabilité dans la base CVE