CVE-2025-67846

Published: Dic 19, 2025 Last Modified: Gen 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,9
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: changed
Confidentiality: low
Integrity: low
Availability: none

Description

AI Translation Available

The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contains unpatched vulnerabilities. By browsing directly to the specific git-ref or deployment-id subdomain, the attacker can force the application to load the vulnerable version.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0005
Percentile
0,1th
Updated

EPSS Score Trend (Last 87 Days)

472

External Control of Assumed-Immutable Web Parameter

Draft
Common Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Modify Application Data
Applicable Platforms
Technologies: Web Based, Web Server
View CWE Details
Application

Mintlify by Mintlify

Version Range Affected
To 2025-11-15 (exclusive)
cpe:2.3:a:mintlify:mintlify:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://kibty.town/blog/mintlify/
https://news.ycombinator.com/item?id=46317098
https://www.mintlify.com/blog/working-with-security-researchers-november-2025
https://www.mintlify.com/docs/changelog