On January 28, 2026, security researcher BobDaHacker discovered that the AI meeting transcription platform tl;dv had a broken tenant isolation in its Firestore database: any logged-in user could query all 181,874 meeting records on the platform, including about 1,000 real-time meeting IDs from in-progress calls that could be joined without an invite. Six months after the report, the vulnerability is still live.
A Forgotten Collection — 180,000 Meetings Left Wide Open
181,874 meeting records, 84,312 unique users, and any logged-in user can crash in-progress calls in real time. Six months later, the vulnerability is still live.
tl;dv is an AI meeting recording platform that drops a bot into your Google Meet, Zoom, or Teams calls, records everything, transcribes it, and generates AI summaries. It claims over 2 million users, has heavyweight investors behind it, and is pushed by half the LinkedIn sales-influencer crowd. People use it to record sales calls, job interviews, performance reviews, and internal strategy meetings — the kind where someone says "this call is being recorded," everyone chuckles awkwardly, and then spends 45 minutes discussing trade secrets.
The flaw sits in the authentication flow. When a user signs up, the platform issues a JWT, which is then exchanged for a Firebase token via gw.tldv.io/v1/users/firebase/token. That token is used to query their Firestore database. The problem: the meetings collection has no tenant isolation. Any authenticated tl;dv user can pull every meeting record from every account on the platform. Each record comes with the creator's email, the meeting ID (a joinable Google Meet or Teams room), the provider, the recording status, and a timestamp.
The real-time aspect makes it worse. A meeting with a status of "recording" has a meeting ID that is a live, in-progress call. An attacker can monitor this collection in real time, see a meeting start recording, grab the ID, and walk right in uninvited. At any given moment, roughly 1,000 meetings sit in the collection with a "recording" status. An attacker running a script could join all 1,000 of them simultaneously.
Verification was straightforward. He pulled a meeting ID from Firestore and joined a live Google Meet for Malaysia's Ministry of Education. A woman was giving a presentation to 157 participants; tl;dv's bot was already in the participant list, and he joined too — no one invited him, Firestore did.
He also joined a meeting where students at a top US university were building a startup app: 21 people online, screensharing the entire project, discussing the prototype, and talking about adding client-side validation for .edu email addresses. They were configuring Supabase live, and BobDaHacker could only hope "please, set some RLS policies" — most people don't, and that's exactly how you end up like tl;dv.
How big is the scope? He queried the meetings collection: 181,874 meeting records, belonging to 84,312 unique users, spanning 35,003 email domains. Government meetings across 23 countries — Brazil, Colombia, Peru, Ukraine, El Salvador, the Philippines, Chile, Indonesia, Mexico, the US, Qatar, Malaysia, Uzbekistan, Sri Lanka, Haiti, South Africa, Jamaica, Honduras, Argentina, Thailand, Japan, Israel, Belize — all on .gov domains. University meetings from dozens of .edu and .ac domains, including Berkeley, the University of Tokyo, De La Salle, and Universidad Nacional de Colombia. Enterprise meetings cover the remaining 35,000 domains: Mitsui-Soko (484 meetings across four regional offices), Mitsui Fudosan, HubSpot, Confluent, Mekari, AnyMind Group. The peak month was July 2025, with 43,209 meetings. The busiest slot: Wednesday at 2:00 PM UTC, with 7,804 meetings — prime weekly standup time.
Meetings are private by default, so video and transcript content aren't visible. But he grabbed 27,334 meeting IDs to check which were public, and over 1,000 were. 715 invitee emails were exposed across 228 domains. Among them: a Brazilian government conservation meeting (PACTO Mata Atlântica) with participants from WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government; a meeting from Ukraine's Ministry of Digital Transformation; a HubSpot sales call; meetings from Universidad Nacional de Colombia and Chile's Cámara Verde.
BobDaHacker reached out to Raphael Allstadt via LinkedIn on January 28 and got a reply within minutes: "Thank you! Can you report it to our CTO? We'll handle it right away." He sent the email. They said "Thanks!" He asked about a bounty. "My CTO will get back to you." But the CTO never responded. January 29: "Your CTO still hasn't contacted me, and the vulnerability isn't fixed." January 30, Raphael: "I'm sure the team will review it soon ❤️" February 14: "Haven't received any emails; the vulnerability is still live." Raphael: "He'll reply ☺️" February 19: "We're on it. It'll take some time, but rest assured we're following up." March 6: "Still not fixed." Read, no reply. July 22: "Still not fixed…" No reply. Six months have passed, and the Firestore database remains wide open. Their security page is lined with trophies: SOC2 compliant, GDPR compliant, EU AI Act compliant — compliance certificates plastered all over the wall, but the database door was never locked.
180,000 Records, 23 Governments — All Visible to a Single Login
tl;dv's database contains every meeting record from the day described above — any registered user, even on the free tier, can browse through them one by one.
Meeting metadata is just the first layer. The researcher grabbed 27,334 meeting IDs to check their public status. Over 1,000 had video or transcripts publicly viewable. 715 invitee emails were exposed across 228 domains.
In the participant list of a Brazilian government environmental meeting (PACTO Mata Atlântica), WWF, The Nature Conservancy, Conservation International, WRI, and the São Paulo state government all show up. A meeting from Ukraine's Ministry of Digital Transformation was in there too.
The most counterintuitive part: this isn't some sophisticated attack. No password cracking, no zero-day exploit — just sign up for a tl;dv account, grab a Firebase token, and query the meetings collection. Tenant isolation was never implemented.
The researcher reported the issue on January 28, 2026, followed up on July 22, and got nothing. The CTO never replied to a single email.