Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-67842

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.4%
CVSS Severity
CVSS v3 Score 6.4
Products affected by CVE-2025-67842


Contact Us

Shodan ® - All rights reserved