Skip to content
CursorGHSA-rjmc-526x-8653

IDOR in Usage Events API Lets Users Access Teammates' Activity Data

Medium4.3Published Jun 19, 2025

**Summary** An IDOR (Insecure Direct Object Reference) vulnerability in the /api/dashboard/get-filtered-usage-events website endpoint allowed any authenticated team member to access other teammates' usage data by modifying the userId in the request. **Impact** This flaw exposes private usage data of any teammate, including timestamps, usage numbers, and model choices. **Remediation** The endpoint has been restricted as of 2025-06-17 to only administrators for users on teams.

GitHub advisory

Affected versions

PackageAffectedFixed in
Cursor API
Product
< 2025-06-172025-06-17
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-639

More Cursor advisories

All Cursor
Advisory
Bypassing allow list to execute an arbitrary command
Medium6.4Aug 1, 2025
Arbitrary Image Fetch in Mermaid Diagram Tool
Medium4.4Aug 1, 2025
MCP Install Deeplink Did Not Show Arguments on User-Dialog
MediumAug 1, 2025
Modification of MCP Server Definitions Bypasses Manual Re-approval
High7.2Aug 1, 2025
IDOR in Usage API Leading to Unauthorized Data Exposure
Medium4.3Jun 19, 2025
Potential Information Leakage using JSON schema in Cursor Agent
Medium5.9Jun 11, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.