WhisperX tag archive

#API exposure

This page collects WhisperX intelligence signals tagged #API exposure. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-23 09:54:14 · GitHub Issues

1. API Endpoint Exposes Individual User Costs and Identities to All Organization Members

A security vulnerability in the usage reporting API allows any authenticated organization member—including those with minimal viewer permissions—to access detailed per-user spending data and identity information. The affected endpoint, GET /v1/usage, returns a `top_users` array containing each user's UUID, request coun...