Remote Code Execution Vulnerability in Mintlify Platform
CVE-2025-67846
What is CVE-2025-67846?
The Deployment Infrastructure in the Mintlify Platform prior to November 15, 2025, is susceptible to remote code execution attacks. Attackers can bypass security patches implemented in the application and exploit predictable deployment identifiers on the Vercel preview domain. By discerning the URL structure of unpatched previous deployments, attackers can effectively conduct downgrade attacks, forcing the application to revert to and execute vulnerable versions by directly accessing specific git-ref or deployment-id subdomains.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mintlify Platform 0 < 2025-11-15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
