CVE-2025-67846: Medium severity Mintlify Mintlify vulnerability
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contains unpatched vulnerabilities. By browsing directly to the specific git-ref or deployment-id subdomain, the attacker can force the application to load the vulnerable version.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67846?
CVE-2025-67846 is considered a high severity vulnerability due to its potential for remote exploitation and security breach.
How do I fix CVE-2025-67846?
To fix CVE-2025-67846, users should update to Mintlify Platform version 2025-11-15 or later.
What type of attack does CVE-2025-67846 allow?
CVE-2025-67846 allows remote attackers to execute downgrade attacks by bypassing security patches.
What are the affected systems for CVE-2025-67846?
CVE-2025-67846 affects the Mintlify Platform prior to version 2025-11-15.
Is CVE-2025-67846 an exploit for local or remote access?
CVE-2025-67846 is an exploit for remote access, enabling attackers to manipulate deployment identifiers.