Skip to content
CursorGHSA-g4ff-54cv-h6f9

Any Team Member Can Access Billing Link

LowPublished Nov 27, 2024

Prior to Nov 27, 2024, any member of a team was able to access the team's billing page, containing addresses and last 4 card digits of the team's billing admin. This has been patched, and the link is now only available for team admins. ### Details The endpoint https://www.cursor.com/api/portal-team returns a response containing a `portalUrl` parameter that directly links to the billing page. Prior to the Nov 27 patch, this endpoint was accessible to any member of a team, including non-admins, even though the UI on the settings page would hide the link if the user was not an admin. ### Patches A server-side patch to restrict billing access to team admins was deployed on Nov 27, on the same day of receiving the report. ### Workarounds The patch has been applied server-side, so **no additional action is needed**.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor Billing
Product
< AllversionsAllversions
Details and references

More Cursor advisories

All Cursor
Advisory
IDOR in Usage API Leading to Unauthorized Data Exposure
Medium4.3Jun 19, 2025
IDOR in Usage Events API Lets Users Access Teammates' Activity Data
Medium4.3Jun 19, 2025
Potential Information Leakage using JSON schema in Cursor Agent
Medium5.9Jun 11, 2025
Arbitrary file write from Cursor Agent through a prompt injection from malicious @Docs
High8.0Apr 7, 2025
RCE via Prompt Injection Into Cursor's Terminal Cmd-K
HighOct 22, 2024
TCC Bypass in Cursor's macOS Application
Low3.8Sep 24, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.