A critical security vulnerability in the AI meeting platform tl;dv has left the private meeting data of over 84,000 users exposed in an unsecured Firestore database for months.
Key Points
- The vulnerability allows any authenticated user to query the entire "meetings" collection, exposing email addresses, conference IDs, and real-time recording statuses.
- Researchers confirmed the flaw by joining live, uninvited meetings hosted by government entities and universities, including the Malaysian Ministry of Education.
- Data from 35,003 unique domains is affected, including sensitive records from government agencies across 23 countries and major corporations like HubSpot.
- An additional internal application, "World Cup Pick'em," lacks authentication, leaking the full names and corporate email addresses of tl;dv employees.
- Despite multiple disclosures beginning in January 2026, the company has failed to secure the database or respond to security inquiries as of July 2026.