CVE-2025-67846 Details
Description
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contains unpatched vulnerabilities. By browsing directly to the specific git-ref or deployment-id subdomain, the attacker can force the application to load the vulnerable version.
A vulnerability in the Mintlify Platform's Deployment Infrastructure, prior to November 15, 2025, allows remote attackers to bypass security patches and execute downgrade attacks. This is achieved by exploiting predictable deployment identifiers on the Vercel preview domain. Attackers can identify URLs of previous deployments that contain unpatched vulnerabilities and, by directly accessing specific git references or deployment IDs, force the application to load vulnerable versions.
Mintlify has implemented a visitor password on preview deployments on Vercel, purging old deployments that were vulnerable. Instructions for managing Vercel deployments can be found in the Vercel documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://kibty.town/blog/mintlify/ | [email protected] | ExploitThird Party Advisory |
| https://news.ycombinator.com/item?id=46317098 | [email protected] | Issue Tracking |
| https://www.mintlify.com/blog/working-with-security-researchers-november-2025 | [email protected] | Vendor Advisory |
| https://www.mintlify.com/docs/changelog | [email protected] | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-472 | External Control of Assumed-Immutable Web Parameter | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mintlify mintlify | < 2025-11-15 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 2, 2026 | Initial Analysis | [email protected] |
| Dec 19, 2025 | New CVE Received | [email protected] |