Skip to content
CursorGHSA-c43p-6fv2-6gr2

IDOR in Usage API Leading to Unauthorized Data Exposure

Medium4.3Published Jun 19, 2025

**Summary** An Insecure Direct Object Reference (IDOR) vulnerability existed in the /api/dashboard/get-monthly-invoice endpoint. This flaw allows any authenticated team member to retrieve invoice and usage data for the entire team, regardless of their authorization level. **Impact** This flaw exposed private usage and cost data of all team members regardless of role within the team. **Remediation** The endpoint has been restricted as of 2025-06-17 to only administrators for users on teams.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor API
Product
< 2025-06-172025-06-17
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-639

More Cursor advisories

All Cursor
Advisory
Bypassing allow list to execute an arbitrary command
Medium6.4Aug 1, 2025
Arbitrary Image Fetch in Mermaid Diagram Tool
Medium4.4Aug 1, 2025
MCP Install Deeplink Did Not Show Arguments on User-Dialog
MediumAug 1, 2025
Modification of MCP Server Definitions Bypasses Manual Re-approval
High7.2Aug 1, 2025
IDOR in Usage Events API Lets Users Access Teammates' Activity Data
Medium4.3Jun 19, 2025
Potential Information Leakage using JSON schema in Cursor Agent
Medium5.9Jun 11, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.