Every public Notion page exposes every editor's email address
Key point
Public Notion pages leak editors' emails and photos without authentication.
Details
On public Notion pages, editor UUIDs are exposed without authentication, and with just one POST request, you can even confirm name, email, and profile photo.
On the Notion Community page, 12 out of 13 user IDs yielded emails, and the targets included Notion employees, service accounts like [email protected], and even external contractors.
This process required no cookies, no tokens, and no authentication procedure, and getLoginOptions was also called without authentication, making it possible to distinguish whether each account used password login or SSO.
The scope of impact is broad, covering company wikis, hiring documents, public documentation, and onboarding guides that use public Notion pages. A simple site:notion.site search alone reveals thousands of public pages, and because there is no rate limiting and batch processing of 50 people at a time is possible, a set of company email addresses can be easily extracted for large workspaces.
The issue was first reported to HackerOne on July 28, 2022, but remained unfixed for nearly 4 years. Re-verification showed the same endpoint and the same unauthenticated behavior persisted; it was marked as informative on HackerOne, and per the original source, there was neither a CVE nor a bug bounty.
Organizations operating public Notion pages should review their sharing settings again, and should operate under the assumption that editor PII may be exposed upon public publishing.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.