会议记录笔记平台tl;dv的Firestore数据库存在租户隔离缺陷,导致任何认证用户可以查询平台上的全部会议记录[1]。这一漏洞暴露了181,874条会议记录、来自84,312个唯一用户的信息,涉及35,003个邮箱域[1]。根据安全研究人员的发现,泄露的会议数据涵盖23个国家的政府机构,包括巴西、哥伦比亚、秘鲁、乌克兰和菲律宾等[1];还包括伯克利、东京大学等高校,以及HubSpot、Confluent等企业的会议记录,其中Mitsui-Soko公司共有484条会议记录暴露[1]。
研究人员于2026年1月28日向tl;dv报告了这一漏洞,但截至文章发布时已过六个月,问题仍未得到修复[1]。在此期间,研究人员与公司CTO的沟通也无果而终[1]。调查显示,平台上有超过1,000条公开会议可被访问,其中715条邀请人的邮箱地址已暴露[1]。研究人员成功加入了两场未被邀请的会议——马来西亚教育部会议和一场美国大学创业项目会议——进一步证实了漏洞的严重性[1]。据统计,2025年7月是泄露数据的高峰期,当月共有43,209条会议记录[1]。tl;dv平台声称拥有超200万用户,并宣称获得SOC2认证、符合GDPR和欧盟AI法案的要求[1]。
A critical security vulnerability in the note-taking and meeting recording platform tl;dv has left more than 181,000 meeting recordings accessible to unauthorized users.[1] Researchers discovered that the platform's Firestore database lacked proper tenant isolation, allowing any authenticated user to query all 181,874 meeting records stored on the system, affecting 84,312 unique users across 35,003 email domains.[1] The vulnerability was reported on January 28, 2026, but remained unpatched six months after disclosure, with communications to the platform's Chief Technology Officer yielding no resolution.[1]
The exposed data spans sensitive organizational contexts. Government meetings involving 23 countries—including Brazil, Colombia, Peru, Ukraine, and the Philippines—were accessible, as were university recordings from institutions such as UC Berkeley and the University of Tokyo.[1] Corporate meetings from companies including HubSpot and Confluent were also compromised, with logistics company Mitsui-Soko alone having 484 exposed meeting records.[1] The database contained over 1,000 publicly accessible meetings, with email addresses of 715 invitees exposed.[1] Researchers demonstrated the severity by successfully joining two meetings without invitation: a Malaysian Ministry of Education session and a U.S. university entrepreneurship program meeting.[1]
Activity on the platform peaked in July 2025 with 43,209 meetings recorded that month.[1] Despite tl;dv's claims of serving over 2 million users and maintaining SOC2 certification, GDPR compliance, and EU AI Act compliance, the prolonged unresolved vulnerability raises significant questions about the platform's security infrastructure.[1]