- CSRF delte other's apikeys with 1-click
- IDOR in
workspaceID=Leads to Get Other's APIKey - IDOR Edit Others APIKey Details
- Privilege Escalations Like Guest member can read/edit/delete api keys in the organization
- Admin generated APIKey and then got downgraded to member but still can access/use the old apikey he made