Mintlify records
5 published records for vendor mintlify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine1
- CWE-24 Path Traversal: '../filedir'1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-472 External Control of Assumed-Immutable Web Parameter1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-67843No exploit | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attacmintlify · mintlify · CWE-1336 | Critical9.8 | — | 1.1% | Dec 18, 2025 |
26Monitor | CVE-2025-67846No exploit | The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgradmintlify · mintlify · CWE-472 | Medium6.5 | — | 0.4% | Dec 18, 2025 |
21Monitor | CVE-2025-67845No exploit | A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to injmintlify · mintlify · CWE-24 | Medium5.4 | — | 0.5% | Dec 18, 2025 |
21Monitor | CVE-2025-67842No exploit | The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomainmintlify · mintlify · CWE-829 | Medium5.4 | — | 0.4% | Dec 18, 2025 |
17Monitor | CVE-2025-67844No exploit | The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the remintlify · mintlify · CWE-425 | Medium4.3 | — | 0.4% | Dec 18, 2025 |
- CVE-2025-6784339Monitor
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attac
CriticalCVSS 9.8No exploitEPSS 1%mintlify · mintlifyDec 18, 2025
- CVE-2025-6784626Monitor
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrad
MediumCVSS 6.5No exploitEPSS 0%mintlify · mintlifyDec 18, 2025
- CVE-2025-6784521Monitor
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inj
MediumCVSS 5.4No exploitEPSS 1%mintlify · mintlifyDec 18, 2025
- CVE-2025-6784221Monitor
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain
MediumCVSS 5.4No exploitEPSS 0%mintlify · mintlifyDec 18, 2025
- CVE-2025-6784417Monitor
The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the re
MediumCVSS 4.3No exploitEPSS 0%mintlify · mintlifyDec 18, 2025