frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: Fiverr left customer files public and searchable

102•morpheuskafka•2h ago
Fiverr (gig work/task platform, competitor to Upwork) uses a service called Cloudinary to process PDF/images in messaging, including work products from the worker to client.

Besides the PDF processing value add, Cloudinary effectively acts like S3 here, serving assets directly to the web client. Like S3, it has support for signed/expiring URLs. However, Fiverr opted to use public URLs, not signed ones, for sensitive client-worker communication.

Moreover, it seems like they may be serving public HTML somewhere that links to these files. As a result, hundreds are in Google search results, many containing PII.

Example query: site:fiverr-res.cloudinary.com form 1040

In fact, Fiverr actively buys Google Ads for keywords like "form 1234 filing" despite knowing that it does not adequately secure the resulting work product, causing the preparer to violate the GLBA/FTC Safeguards Rule.

Responsible Disclosure Note -- 40 days have passed since this was notified to the designated vulnerability email (security@fiverr.com). The security team did not reply. Therefore, this is being made public as it doesn't seem eligible for CVE/CERT processing as it is not really a code vulnerability, and I don't know anyone else who would care about it.

Comments

mtmail•2h ago
You followed the correct reporting instructions.

https://www.fiverr.com/.well-known/security.txt only has "Contact: security@fiverr.com" and in their help pages they say "Fiverr operates a Bug Bounty program in collaboration with BugCrowd. If you discover a vulnerability, please reach out to security@fiverr.com to receive information about how to participate in our program."

wxw•2h ago
Wow, surprised this isn't blowing up more. Leaking form 1040s is egregious, let alone getting them indexed by Google...
mraza007•1h ago
Woah that's brutal all the important information is wild in public
BoredPositron•40m ago
Just by scrolling over it that's really rough.
popalchemist•32m ago
Burn it to the ground.
smashah•24m ago
They bought and.co and then dropped it. strange company
iwontberude•19m ago
Loooool what a mess
impish9208•9m ago
This is crazy! So many tax and other financial forms out in the open. But the most interesting file I’ve seen so far seems to be a book draft titled “HOOD NIGGA AFFIRMATIONS: A Collection of Affirming Anecdotes for Hood Niggas Everywhere”. I made it to page 27 out of 63.
onraglanroad•1m ago
I've read worse. Better than Dan Brown!

Pope Leo XIV covered up cases of child abuse in Peru and Chicago

1•0ut0flin3•35s ago•0 comments

Zelensky: Ukraine's defense industry can produce FPV drones annually

https://www.ukrinform.net/rubric-defense/4112129-zelensky-ukraines-defense-industry-can-produce-m...
1•doener•3m ago•0 comments

Comparison of Payment Methods

https://eylenburg.github.io/payments.htm
1•Cider9986•3m ago•0 comments

Terminator: Code You See Onscreen [video]

https://www.youtube.com/watch?v=NebvccLHutQ
1•ingve•3m ago•0 comments

Data Discovery – plain-English to discovering and acquiring data using AI

https://datris.ai/videos/data-discovery-ingestion-consumption
1•tfearn•4m ago•1 comments

Patches for Linux 7.1 May Have Negative Impact on 32-Bit Systems

https://www.phoronix.com/news/Linux-7.1-VFS-Kino-32-bit
1•doener•5m ago•0 comments

How to diagnose RAG failures from traces

https://www.siquick.com/blog/diagnose-rag-failures-from-traces
1•siquick•12m ago•0 comments

Did games really get more costly to make?

https://newsletter.hushcrasher.com/p/did-games-really-get-more-costly
1•juliebelz•13m ago•1 comments

Stack Overflow moderator publicly leaks private flagger information

https://meta.stackoverflow.com/questions/438679/why-is-a-moderator-harassing-me-about-an-answer-i...
2•hskdididn•14m ago•0 comments

Are ClickHouse JOINs Slow? A 2026 PR-by-PR Analysis

https://dataanalyticsguide.substack.com/p/clickhouse-join-performance-2026
1•manveerc•17m ago•0 comments

Sandyaa: Recursive-LLM source code auditor that writes exploitable PoCs

https://github.com/securelayer7/sandyaa
1•sandeep_kamble•17m ago•1 comments

How Not to 'Pilet' a Kickstarter

https://c33tech.com/blog/2026/04/how_not_to_pilet_a_kickstarter/
1•mikeflynn•18m ago•0 comments

Michael O. Rabin has passed away

https://en.wikipedia.org/wiki/Michael_O._Rabin
2•statusreport•19m ago•1 comments

Connect iMessage to your Claude Code assistant

https://github.com/anthropics/claude-plugins-official/tree/main/external_plugins/imessage
1•rob•19m ago•0 comments

New (Twin) Dad Advice

https://hec.works/blog/new-twin-dad/
2•dividedcomet•21m ago•2 comments

Show HN: Turned a viral DevOps debugging tweet into a playable incident SIM

https://youbrokeprod.com/login?redirect=%2Fplay%2Frunaway-process-001
1•cdnsteve•22m ago•0 comments

Anthropic Redesigns Claude Code Desktop

https://twitter.com/claudeai/status/2044131493966909862
1•Nevin1901•23m ago•1 comments

Show HN: Start Using Claude Managed Agents Today – Posse

https://github.com/oguzbilgic/posse
1•obilgic•24m ago•0 comments

I Went to China to See Its Progress on A.I. We Can't Beat It

https://www.nytimes.com/2026/04/13/opinion/china-ai-america-chipmakers.html
2•suvan•24m ago•1 comments

Show HN: Would you score a podcast debate?

1•fcpguru•25m ago•0 comments

California moves forward with its 'Stop Nick Shirley Act'

https://www.deseret.com/politics/2026/04/14/stop-nick-shirley-act-california-fraud/
3•donsupreme•27m ago•1 comments

Agent Skill for Jj Jujutsu VCS

https://github.com/danverbraganza/jujutsu-skill
1•nvader•30m ago•0 comments

Android IRCx

https://github.com/AndroidIRCx/AndroidIRCx
1•sans_souse•31m ago•0 comments

Lisp is Not an Acceptable Lisp (2006)

https://steve-yegge.blogspot.com/2006/04/lisp-is-not-acceptable-lisp.html
2•fyskij•32m ago•1 comments

TN's Charlie Kirk Act bans student walkouts, protects conservative speakers

https://wpln.org/post/tennessees-charlie-kirk-act-bans-student-walkouts-protects-conservative-spe...
4•bediger4000•34m ago•5 comments

The Timeless Way of Building

https://en.wikipedia.org/wiki/The_Timeless_Way_of_Building
1•gradus_ad•34m ago•1 comments

Cozy landing page I liked

https://www.chloeyan.me/
1•Akcium•34m ago•0 comments

Tech History: Looms taught us to store, share, and "run" logic

https://cyrusradfar.com/thoughts/thread
1•cyrusradfar•35m ago•1 comments

Amazon to acquire Globalstar in $11.6B satellite bet

https://www.bloomberg.com/news/articles/2026-04-14/amazon-to-buy-satellite-operator-globalstar-fo...
1•samaysharma•35m ago•0 comments

How Poor Am I?

https://howpoorami.org
1•gaws•36m ago•0 comments