CursorGHSA-c43p-6fv2-6gr2
IDOR in Usage API Leading to Unauthorized Data Exposure
Medium4.3Published Jun 19, 2025
**Summary** An Insecure Direct Object Reference (IDOR) vulnerability existed in the /api/dashboard/get-monthly-invoice endpoint. This flaw allows any authenticated team member to retrieve invoice and usage data for the entire team, regardless of their authorization level. **Impact** This flaw exposed private usage and cost data of all team members regardless of role within the team. **Remediation** The endpoint has been restricted as of 2025-06-17 to only administrators for users on teams.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor API Product | < 2025-06-17 | 2025-06-17 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-639
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 12025 | Bypassing allow list to execute an arbitrary command | Medium6.4 | 1.3 |
| Aug 12025 | Arbitrary Image Fetch in Mermaid Diagram Tool | Medium4.4 | 1.3 |
| Aug 12025 | MCP Install Deeplink Did Not Show Arguments on User-Dialog | Medium | 1.3 |
| Aug 12025 | Modification of MCP Server Definitions Bypasses Manual Re-approval | High7.2 | 1.3 |
| Jun 192025 | IDOR in Usage Events API Lets Users Access Teammates' Activity Data | Medium4.3 | 2025-06-17 |
| Jun 112025 | Potential Information Leakage using JSON schema in Cursor Agent | Medium5.9 | 0.51.0 |