tl;dv, an AI-powered meeting assistant for video conferences, left metadata for 181,874 meetings accessible for months. A security researcher reported the vulnerability in January 2026, and the company reportedly did not respond for half a year. Accounts of more than 84,000 users from over 35,000 email domains were affected.
Firestore database reveals foreign conference data worldwide
The security researcher, who publishes under the name BobDaHacker, found the cause in tl;dv’s Cloud Firestore database: it lacked tenant separation between accounts. Therefore, any logged-in user could query the complete collection of all meeting records on the platform using a regular access token, regardless of their own account. Each record contained the email address of the meeting creator, the video service used, and the recording status. Additionally, there was a conference ID through which the corresponding Google Meet or Microsoft Teams room could be directly accessed. According to the researcher, around 1,000 meetings with an active recording status were in the database at any given time, and their conference IDs were live usable. He was able to join, among other things, a session of the Malaysian Ministry of Education and a meeting with more than 150 participants.
Among the more than 35,000 affected email domains, the researcher identified government agencies from 23 countries, including Brazil, Ukraine, the Philippines, and the USA. Universities such as UC Berkeley and the University of Tokyo were also affected, as well as companies like HubSpot. On an internally used, also unprotected tl;dv subdomain for a football prediction game, he also found names and company email addresses of 19 of the company’s own employees. The total number of more than 181,000 documented meetings comes solely from the researcher’s evaluation and is independently unverified. He first informed tl;dv on January 28, 2026, through a contact on LinkedIn. Feedback from the responsible Chief Technology Officer had not been received by the end of July despite multiple inquiries. It was only with the publication of his report on August 4 that the case became public.
tl;dv closes second, previously unknown vulnerability
tl;dv states in its own statement that an initial variant of the vulnerability had already been fixed months before the publication and confirmed by an external penetration testing service provider. A second access method, previously unknown to the company, was closed within 24 hours of becoming known. Only metadata such as meeting and conference IDs and email addresses had been accessible, according to the company. Passwords, recordings, transcripts, AI-generated notes, and billing data had never been accessible. CTO Allan Bettarel also admitted that he had not adequately informed the researcher after the initial report and took responsibility for it. As an additional consequence, tl;dv completely removed Firebase from its own infrastructure.
The case is part of a growing list of security vulnerabilities in AI tools that employees often use without review by the IT department. Similar cases recently affected Atlassian’s assistant Rovo and an AI-assisted SharePoint vulnerability. It remains open whether certifications such as SOC 2 or a GDPR compliance declaration, which tl;dv claims to possess, will be more closely scrutinized in the future when selecting such tools. In the current case, they certainly did not prevent the months-long open vulnerability.


