Security Advisory

CVE-2025-67842

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-19 00:00:00
Last updated 2025-12-23 19:44:13
Assigner mitre
State PUBLISHED

Description

The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenants assets can be served on any other tenants documentation site.