Skip to content

Any Team Member Can Access Billing Link

Low
arvid220u published GHSA-g4ff-54cv-h6f9 Nov 27, 2024

Package

Cursor Billing

Affected versions

< Nov 27, 2024

Patched versions

All versions, post Nov 27

Description

Prior to Nov 27, 2024, any member of a team was able to access the team's billing page, containing addresses and last 4 card digits of the team's billing admin. This has been patched, and the link is now only available for team admins.

Details

The endpoint https://www.cursor.com/api/portal-team returns a response containing a portalUrl parameter that directly links to the billing page. Prior to the Nov 27 patch, this endpoint was accessible to any member of a team, including non-admins, even though the UI on the settings page would hide the link if the user was not an admin.

Patches

A server-side patch to restrict billing access to team admins was deployed on Nov 27, on the same day of receiving the report.

Workarounds

The patch has been applied server-side, so no additional action is needed.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits