Directory Traversal Vulnerability in Mintlify Platform
CVE-2025-67845

6.4MEDIUM

Key Information:

Vendor

Mintlify

Vendor
CVE Published:
19 December 2025

What is CVE-2025-67845?

A directory traversal vulnerability exists in the Static Asset Proxy Endpoint of the Mintlify Platform. This flaw enables remote attackers to potentially execute arbitrary web scripts or HTML through the manipulation of URL paths, specifically with crafted sequences that exploit the vulnerability. Such an attack could compromise the security of the platform by allowing unauthorized access to sensitive data or the injection of malicious content.

Affected Version(s)

Mintlify Platform 0 < 2025-11-15

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67845 : Directory Traversal Vulnerability in Mintlify Platform