tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security researcher discovered a critical Firestore misconfiguration in tl;dv, an AI meeting recording platform with over 2 million users. Due to missing tenant isolation rules on the meetings collection, any authenticated tl;dv user could query all 181,874 meeting records from 84,312 users across 35,003 domains — including live conference IDs for ongoing calls. The researcher demonstrated the flaw by joining two live meetings uninvited, including a Malaysian Ministry of Education session with 157 participants. Government meetings from 23 countries and universities worldwide were exposed. Over 1,000 meetings were publicly accessible with invitee emails visible. A secondary finding revealed an internal World Cup prediction app with no authentication, leaking employee names and emails. Despite responsible disclosure in January 2026, the vulnerability remained unpatched six months later with the CTO never responding.