CVE-2025-67844
The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields.
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the specific GitHub App Installation ID associated with the user's organization.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.40% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-425
- Affected
- mintlify/mintlify
- Source
- cve@mitre.org
References
- https://kibty.town/blog/mintlify/Exploit, Third Party Advisory
- https://news.ycombinator.com/item?id=46317098Issue Tracking
- https://www.mintlify.com/blog/working-with-security-researchers-november-2025Vendor Advisory
- https://www.mintlify.com/docs/changelogRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.