Security

tl;dv exposes 181,874 meetings over six months

3 min read

TL;DR Too Long; Didn’t read

According to a security researcher, the AI meeting assistant tl;dv left metadata for 181,874 meetings unprotected in its database for months. Accounts from more than 35,000 email domains were affected, including government agencies from 23 countries. The researcher reported the finding in January 2026, and tl;dv admitted to responding only after the publication in August, closing an additional gap within a day.

A tl;dv logo sticker is affixed to a digital filing cabinet door standing ajar, with colorful video-conference tiles showing tiny silhouetted people streaming out through the gap Image generated with GPT Image 2

Key takeaways

  • 181,874 meeting records from over 35,000 domains were reportedly accessible without access protection.
  • A lack of tenant separation in the Firestore database allowed any logged-in user access to foreign meetings.
  • Conference IDs reportedly made joining ongoing Google Meet and Teams sessions possible.
  • The researcher reported the vulnerability on January 28, 2026, and tl;dv reportedly responded only months later.
  • After the publication, tl;dv closed a second, previously unknown access variant within 24 hours.
  • Passwords, recordings, and billing data remained inaccessible at all times, according to company statements.

tl;dv, an AI-powered meeting assistant for video conferences, left metadata for 181,874 meetings accessible for months. A security researcher reported the vulnerability in January 2026, and the company reportedly did not respond for half a year. Accounts of more than 84,000 users from over 35,000 email domains were affected.

Firestore database reveals foreign conference data worldwide

The security researcher, who publishes under the name BobDaHacker, found the cause in tl;dv’s Cloud Firestore database: it lacked tenant separation between accounts. Therefore, any logged-in user could query the complete collection of all meeting records on the platform using a regular access token, regardless of their own account. Each record contained the email address of the meeting creator, the video service used, and the recording status. Additionally, there was a conference ID through which the corresponding Google Meet or Microsoft Teams room could be directly accessed. According to the researcher, around 1,000 meetings with an active recording status were in the database at any given time, and their conference IDs were live usable. He was able to join, among other things, a session of the Malaysian Ministry of Education and a meeting with more than 150 participants.

Among the more than 35,000 affected email domains, the researcher identified government agencies from 23 countries, including Brazil, Ukraine, the Philippines, and the USA. Universities such as UC Berkeley and the University of Tokyo were also affected, as well as companies like HubSpot. On an internally used, also unprotected tl;dv subdomain for a football prediction game, he also found names and company email addresses of 19 of the company’s own employees. The total number of more than 181,000 documented meetings comes solely from the researcher’s evaluation and is independently unverified. He first informed tl;dv on January 28, 2026, through a contact on LinkedIn. Feedback from the responsible Chief Technology Officer had not been received by the end of July despite multiple inquiries. It was only with the publication of his report on August 4 that the case became public.

tl;dv closes second, previously unknown vulnerability

tl;dv states in its own statement that an initial variant of the vulnerability had already been fixed months before the publication and confirmed by an external penetration testing service provider. A second access method, previously unknown to the company, was closed within 24 hours of becoming known. Only metadata such as meeting and conference IDs and email addresses had been accessible, according to the company. Passwords, recordings, transcripts, AI-generated notes, and billing data had never been accessible. CTO Allan Bettarel also admitted that he had not adequately informed the researcher after the initial report and took responsibility for it. As an additional consequence, tl;dv completely removed Firebase from its own infrastructure.

The case is part of a growing list of security vulnerabilities in AI tools that employees often use without review by the IT department. Similar cases recently affected Atlassian’s assistant Rovo and an AI-assisted SharePoint vulnerability. It remains open whether certifications such as SOC 2 or a GDPR compliance declaration, which tl;dv claims to possess, will be more closely scrutinized in the future when selecting such tools. In the current case, they certainly did not prevent the months-long open vulnerability.

Frequently asked questions

Is tl;dv now safely usable?

According to the company, both known access routes have been closed, the second variant since August 5, 2026. An independent confirmation by third parties is not yet available.

Were recordings or transcripts accessible?

According to tl;dv, no. Only metadata such as email addresses, timestamps, and conference IDs were reportedly accessible, not the actual recordings or AI notes.

Why was the researcher able to join foreign meetings live?

The exposed conference IDs directly referred to unprotected Google Meet or Teams rooms. Anyone who knows such an ID can join the respective meeting without further authorization.

How does this case differ from other AI tool vulnerabilities this summer?

Unlike attacks on AI agents themselves, the cause here was a classic misconfiguration of the database – a fundamental error, independent of the AI functions of the product.

What should companies do now?

Security teams should check which AI meeting tools employees are using and verify their access rights and privacy commitments independently of marketing claims and certifications.

Sources (3)
  1. BobDaHacker: tl;dv (Too Lazy; Didn't Validate) – 181,874 Meetings Left Wide Open
  2. tl;dv: Our thoughts on the darkreading.com article
  3. OffSeq Threat Radar: AI Notetaker Exposes Government, Corporate Video Calls

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog