Intel

AIKIDO-2025-10968

mintlify is vulnerable to Use of third-party component with multiple disclosed vulnerabilities

Use of third-party component with multiple disclosed vulnerabilitiesCVE-2025-67842

50

Medium Risk

This Affects:

JSmintlify
0.1.0 - 4.2.210
Fixed in 4.2.211

TL;DR

Affected versions of this package are vulnerable to a chain of security flaws including cross-tenant static asset access, a path traversal bypass, insecure cross-domain data endpoints, server-side rendering code execution, a site downgrade attack, and an IDOR in the dashboard. An attacker could exploit these in concert, for instance by uploading a malicious SVG via one vulnerability to execute cross-site scripting (XSS) on another customer's domain, potentially compromising user sessions and data. All issues have been fixed; the maintainer has added a deprecation notice on npm installs for vulnerable versions, and users must upgrade immediately.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mintlify is vulnerable to Use of third-party component with multiple disclosed vulnerabilities in versions 0.1.0 - 4.2.210.

How to fix this

Upgrade the mintlify library to the patch version.