Description
A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.
Problem types
Product status
Timeline
| 2026-03-21: | Advisory disclosed |
| 2026-03-21: | VulDB entry created |
| 2026-03-21: | VulDB entry last update |
Credits
Ghufran Khan (VulDB User)
VulDB
References
vuldb.com/?id.352376 (VDB-352376 | mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization)
vuldb.com/?ctiid.352376 (VDB-352376 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.774806 (Submit #774806 | mickasmt next-saas-stripe-starter 1.0.0 Authorization Bypass)