Notion's public pages expose editor email addresses

Hacker News·1mo·Tiberium

A security researcher discovered that Notion leaks the email addresses of all editors on any publicly shared page through an unauthenticated API endpoint. For indie makers using Notion for documentation, landing pages, or collaborative content, this is a meaningful privacy gap worth auditing your public workspace settings.

Related stories