AI Briefing
KO

Tell HN: Fiverr left customer files public and searchable

·2026.04.15 03:56

Key point

Fiverr's public URL settings on Cloudinary exposed customer files to search engines.

Details

Fiverr uses Cloudinary to handle PDFs and images in messages, and uses it to pass work deliverables between freelancers and customers.

The problem is that it used public URLs instead of signed/expiring URLs for sensitive files. Because of this, Cloudinary effectively functioned like S3 but without proper access control in place, and some files could be viewed directly from the web.

Additionally, it appears that public HTML somewhere links to these files, and as a result hundreds of them were exposed in Google search results. Some of the exposed documents contained PII.

As an example, a search query like site:fiverr-res.cloudinary.com form 1040 was given.

The author stated that after reporting the issue to the designated security email ([email protected]), they waited 40 days but received no response. They explained that they concluded this wasn't subject to CVE/CERT handling and disclosed it accordingly.

They also criticized Fiverr for running Google Ads on keywords like "form 1234 filing" while failing to adequately secure deliverables, thereby shifting the risk of GLBA / FTC Safeguards Rule violations onto freelancers.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.