Unrated severityNVD Advisory· Published Dec 19, 2025· Updated Dec 23, 2025
CVE-2025-67842
CVE-2025-67842
Description
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
Affected products
2- Range: <2025-11-15
- Mintlify/Mintlify Platformv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.