Skip to main content

CVE-2025-67843

8.3
HIGHCVSS v3.1 Base Score
0.82%
LOW RiskEPSS (75th percentile)

A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file.

Published: 12/19/2025
Modified: 1/2/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.3HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

EPSS Score (Exploitation Probability)

0.82%LOW Exploitation Risk
75th percentile

This vulnerability has a 0.82% probability of being exploited in the next 30 days, ranking higher than 75% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-1336)

CVE-2026-21450CRITICAL 9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

1/2/2026
CVE-2026-21448CRITICAL 9.8

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a patch.

1/2/2026
CVE-2025-68929CRITICAL 9

Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with specific permissions could be tricked into accessing a specially crafted link. This could lead to a malicious template being executed on the server, resulting in remote code execution. Versions 14.99.6 and 15.88.1 fix the issue. No known workarounds are available.

12/29/2025
CVE-2025-59340CRITICAL 9.8

jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary classes. This enables the creation of semi-arbitrary class instances without directly invoking restricted methods or class literals. As a result, an attacker can escape the sandbox and instantiate classes such as java.net.URL, opening up the ability to access local files and URLs(e.g., file:///etc/passwd). With further chaining, this primitive can potentially lead to remote code execution (RCE). This vulnerability is fixed in 2.8.1.

9/17/2025
CVE-2025-49619HIGH 8.5

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).

6/7/2025

Similar SeverityHIGH