CVE-2025-67846
EUVD-2025-20442419.12.2025, 02:16
The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contains unpatched vulnerabilities. By browsing directly to the specific git-ref or deployment-id subdomain, the attacker can force the application to load the vulnerable version.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mintlify | mintlify | 𝑥 < 2025-11-15 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration