Medium severity6.4NVD Advisory· Published Dec 19, 2025· Updated Jun 17, 2026
CVE-2025-67842
CVE-2025-67842
Description
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<2025-11-15+ 1 more
- (no CPE)range: <2025-11-15
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
6- kibty.town/blog/mintlify/nvdExploitThird Party Advisory
- gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28nvdThird Party Advisory
- heartbreak.ingnvdThird Party Advisory
- www.mintlify.com/blog/working-with-security-researchers-november-2025nvdVendor Advisory
- news.ycombinator.com/itemnvdIssue Tracking
- www.mintlify.com/docs/changelognvdRelease Notes
News mentions
0No linked articles in our index yet.