CVE-2026-4549

LOW

mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization

Title source: cna
STIX 2.1

Description

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.

References (3)

Core 3
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-352376 | mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization
https://vuldb.com/?id.352376
Signature, Permissions Required signature permissions-required
VDB-352376 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/?ctiid.352376
Third Party Advisory third-party-advisory
Submit #774806 | mickasmt next-saas-stripe-starter 1.0.0 Authorization Bypass
https://vuldb.com/?submit.774806

Scores

CVSS v3 3.1
EPSS 0.0028
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (1)
mickasmt/next-saas-stripe-starter 1.0.0
Published Mar 22, 2026
Tracked Since Mar 22, 2026