Mintlify Platform Deployment Downgrade Vulnerability

Vulnerability

A vulnerability in the Mintlify Platform's Deployment Infrastructure, prior to November 15, 2025, allows remote attackers to bypass security patches and execute downgrade attacks. This is achieved by exploiting predictable deployment identifiers on the Vercel preview domain. Attackers can identify URLs of previous deployments that contain unpatched vulnerabilities and, by directly accessing specific git references or deployment IDs, force the application to load vulnerable versions.

Impact

Exploitation of this vulnerability allows for the execution of previously patched exploits, potentially leading to cross-site scripting (XSS) vulnerabilities on customer domains, according to Mintlify.

Reproduction

To reproduce this vulnerability, add a specific deployment ID or git reference of a vulnerable version to a Mintlify repository. Once deployed, access the Vercel preview deployment on a Mintlify-provided documentation or custom domain. Then, navigate to the path '/_mintlify/static/[subdomain]/[vulnerable-asset]' to trigger the downgrade attack.

Remediation

Mintlify has implemented a visitor password on preview deployments on Vercel, purging old deployments that were vulnerable. Instructions for managing Vercel deployments can be found in the Vercel documentation.

Added: Dec 19, 2025, 2:18 AM
Updated: Dec 19, 2025, 2:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.3
remediation
0.0
relevance
1.5
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.