Any Team Member Can Access Billing Link
LowPublished Nov 27, 2024
Prior to Nov 27, 2024, any member of a team was able to access the team's billing page, containing addresses and last 4 card digits of the team's billing admin. This has been patched, and the link is now only available for team admins. ### Details The endpoint https://www.cursor.com/api/portal-team returns a response containing a `portalUrl` parameter that directly links to the billing page. Prior to the Nov 27 patch, this endpoint was accessible to any member of a team, including non-admins, even though the UI on the settings page would hide the link if the user was not an admin. ### Patches A server-side patch to restrict billing access to team admins was deployed on Nov 27, on the same day of receiving the report. ### Workarounds The patch has been applied server-side, so **no additional action is needed**.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Cursor Billing Product | < Allversions | Allversions |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Cursor advisories
All Cursor| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 192025 | IDOR in Usage API Leading to Unauthorized Data Exposure | Medium4.3 | 2025-06-17 |
| Jun 192025 | IDOR in Usage Events API Lets Users Access Teammates' Activity Data | Medium4.3 | 2025-06-17 |
| Jun 112025 | Potential Information Leakage using JSON schema in Cursor Agent | Medium5.9 | 0.51.0 |
| Apr 72025 | Arbitrary file write from Cursor Agent through a prompt injection from malicious @Docs | High8.0 | 0.48.7+ |
| Oct 222024 | RCE via Prompt Injection Into Cursor's Terminal Cmd-K | High | Allversions |
| Sep 242024 | TCC Bypass in Cursor's macOS Application | Low3.8 | 0.41.0 |