tl;dv Exposed 181,874 Meeting Records: 6-Month Unfixed Vulnerability Revealed by Bobdahacker
AI Notetaker tl;dv Exposed 181,874 Meeting Records
Security researcher bobdahacker publicly disclosed a critical vulnerability in the AI meeting recording platform tl;dv, which exposed 181,874 meeting records from 84,312 users across 35,003 email domains. This significant flaw, rooted in a lack of tenant isolation, remained unfixed for six months after its initial report to tl;dv on January 28, 2026, with no response from the company's CTO.
Details of the Data Exposure
The vulnerability allowed any authenticated user to query a vast number of meeting records. Beyond the 181,874 records, more than 1,000 meetings were found to be fully public, exposing invitee emails. Additionally, approximately 1,000 live recording sessions had joinable conference IDs, indicating potential real-time access to ongoing meetings.
Bobdahacker demonstrated the extent of this access by successfully joining a live call involving the Malaysian Ministry of Education and a separate session from a US university startup. The exposed data included government meetings from 23 countries, such as Brazil, Ukraine, Malaysia, the Philippines, and the US, highlighting the broad impact of the security lapse.
Unaddressed Security Flaw and Compliance Claims
The security flaw persisted for six months following its initial disclosure on January 28, 2026. During this period, tl;dv continued to display compliance badges for SOC2, GDPR, and the EU AI Act on its platform. The lack of a response from the CTO regarding the reported vulnerability raised concerns about the company's commitment to resolving critical security issues and its adherence to stated compliance standards.
Implications for User Privacy and Data Security
The absence of tenant isolation, a fundamental security measure, meant that user data was not adequately segregated, allowing unauthorized access across different accounts. This type of vulnerability can lead to significant privacy breaches, especially when sensitive discussions, such as those involving government entities or educational institutions, are exposed. The incident underscores the importance of robust security practices and prompt responses to reported vulnerabilities for AI meeting assistant platforms handling confidential information.
Conclusion
The disclosure by bobdahacker regarding the tl;dv vulnerability highlights critical issues in data security and incident response within the AI notetaker industry. The exposure of nearly 182,000 meeting records and the prolonged period without a fix or official response underscore the need for companies to prioritize security measures like tenant isolation and maintain transparent communication with security researchers. Users of tl;dv and similar platforms should remain vigilant about the security practices of the tools they employ for recording and transcribing meetings.
Sources
- GitHub - khaoss85/nullify: Detect and block invisible meeting transcription tools (Granola, Otter.ai, Fireflies, Read.ai). Protect your meeting privacy from AI notetakers recording without consent. · GitHub
- GitHub - tldv-public/tldv-mcp-server · GitHub
- GitHub - barshy/tldv-transcript-extractor-: A simple web tool that extracts clean conversation transcripts from TLDV HTML. Perfect for free TLDV users who want to extract and save meeting transcripts without premium access. Built in 5 minutes with AI assistance (Claude 3.7 Sonnet). · GitHub
- tl;dv wants to help teams get more out of virtual meetings
- Sex toy maker Lovense caught leaking users' email addresses and exposing accounts to takeovers | TechCrunch
Recommended AI tools
AI Undresser
Image Generation
Uncover the hidden truth
Credo AI
Data Analytics
The trusted leader in AI governance
Islam & AI
Conversational AI
Bridging Islam and Artificial Intelligence
AI for daily life
Search & Discovery
Discover how AI can make your life easier
Responsible AI Institute
Scientific Research
Empowering Ethical AI
Was this article helpful?
Found outdated info or have suggestions? Send us a note.