mintlify is vulnerable to Use of third-party component with multiple disclosed vulnerabilities
50
Medium Risk
Affected versions of this package are vulnerable to a chain of security flaws including cross-tenant static asset access, a path traversal bypass, insecure cross-domain data endpoints, server-side rendering code execution, a site downgrade attack, and an IDOR in the dashboard. An attacker could exploit these in concert, for instance by uploading a malicious SVG via one vulnerability to execute cross-site scripting (XSS) on another customer's domain, potentially compromising user sessions and data. All issues have been fixed; the maintainer has added a deprecation notice on npm installs for vulnerable versions, and users must upgrade immediately.
You are affected if you are using a version that falls within the vulnerable range.
mintlify is vulnerable to Use of third-party component with multiple disclosed vulnerabilities in versions 0.1.0 - 4.2.210.
Upgrade the mintlify library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant