Home
MEDIUM: 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before 2025-11-15
affected
Description
A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences.
Problem types
CWE-24 Path Traversal: '../filedir'
Product status
Any version before 2025-11-15
References
www.mintlify.com/docs/changelog
www.mintlify.com/...-with-security-researchers-november-2025
news.ycombinator.com/item?id=46317098
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.