Description
The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site.
Problem types
CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Product status
Any version before 2025-11-15
References
kibty.town/blog/mintlify/
www.mintlify.com/docs/changelog
www.mintlify.com/...-with-security-researchers-november-2025
gist.github.com/...ermondev/5e2cdc32849405fff6b46957747a2d28
news.ycombinator.com/item?id=46317098
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.