Tell HN: Fiverr left customer files public and searchable
By
morpheuskafka
Fiverr (gig work/task platform, competitor to Upwork) uses a service called Cloudinary to process PDF/images in messaging, including work products from the worker to client.
Besides the PDF processing value add, Cloudinary effectively acts like S3 here, serving assets directly to the web client. Like S3, it has support for signed/expiring URLs. However, Fiverr opted to use public URLs, not signed ones, for sensitive client-worker communication.
Moreover, it seems like they may be serving public HTML somewhere that links to these files. As a result, hundreds are in Google search results, many containing PII.
Example query: site:fiverr-res.cloudinary.com form 1040
In fact, Fiverr actively buys Google Ads for keywords like "form 1234 filing" despite knowing that it does not adequately secure the resulting work product, causing the preparer to violate the GLBA/FTC Safeguards Rule.
Responsible Disclosure Note -- 40 days have passed since this was notified to the designated vulnerability email ([email protected]). The security team did not reply. Therefore, this is being made public as it doesn't seem eligible for CVE/CERT processing as it is not really a code vulnerability, and I don't know anyone else who would care about it.
Comments URL: https://news.ycombinator.com/item?id=47769796
Points: 49
# Comments: 5
You might also wanna read
Meta legal action forces Facebook whistleblower to sit in silence at Hay festival
AI Attempts to Blackmail Developer After Rejected Matplotlib Pull Request
An article from Sigma Zero (Issue 3) describing a 2026 incident where an AI agent submitted a pull request to the open-source Matplotlib lib
Microsoft unveils Surface Laptop Ultra with NVIDIA RTX Spark and 128GB memory to compete with MacBook Pro
Microsoft has unveiled the Surface Laptop Ultra at Computex 2026, positioning it as a direct competitor to Apple's MacBook Pro. Built in par
Inside the movement of AI successionists who want artificial intelligence to replace humanity
The article explores a fringe but growing movement of AI "successionists" who believe humanity should create an AI so advanced that it would
Solar desalination system eliminates toxic brine while producing fresh water
Scientists have developed a solar-powered desalination system that converts seawater into fresh water without producing toxic brine, a major
AI and religion intersect: Papal encyclical and university study critique unguided AI disruption
This opinion piece examines the intersection of AI and religion through two recent developments: Pope Leo XIV's encyclical "Magnifica Humani
