URGENT Security Vulnerability, Deleted AI Notetaker recordings remain accessible via direct URL
Andy Rozhylo
I discovered a critical security vulnerability in how AI Notetaker handles video recordings.
The issue: Deleting AI Notetaker video recordings through the Clips Hub UI does not actually remove the files from your storage/CDN. After deletion, the direct URL to the recording still works and the video is accessible to anyone with the link.
What makes this worse: These recordings were created as Personal Notetaker recordings. They were never shared with anyone, not even other workspace members. Despite being private and never shared, anyone with the direct URL can access the video without any authentication. This means private, unshared meeting recordings are effectively public.
Our workspace has 93+ meeting recordings containing highly confidential discussions: executive syncs, finance board meetings, 1:1s, business development calls, and client conversations. Every single one of them is exposed.
Steps to reproduce:
- Open Clips Hub → AI Notetaker
- Delete any recording via the "..." menu → Delete
- Open the direct URL to the deleted recording
- The video still plays, no authentication required
Expected behavior: Private recordings should never be accessible without authentication. Deleted files should be fully removed from storage, returning 403/404.
Actual behavior: Both active and deleted recordings are accessible to anyone via direct link, regardless of sharing settings.
We demand immediate action:
- Revoke public access to all AI Notetaker recording URLs immediately
- Enforce authentication and permission checks on all recording URLs
- Permanently delete files from storage when users delete them from the UI
- Confirm whether any previously deleted recordings have been retained and are still accessible
- Provide a timeline for the fix
This is not a feature request. This is an active data leak affecting every workspace using AI Notetaker. Every minute this remains unpatched, confidential meeting recordings are exposed to the open internet!
Thank you.
Log In