← AssemblyAI

2025 AssemblyAI — indirect exposure via Granola app API key

2025 300 records affected Share on X

Data compromised

Meeting transcripts (text)

Technical writeup

Hard-coded AssemblyAI API key in Granola macOS Electron app. Accessible via unauthenticated /get-feature-flags endpoint. Tenable researcher demonstrated: key allowed enumeration of /transcript API to download text transcripts for other Granola users. ~300 alpha users affected. Granola revoked key within minutes. No audio accessible, only text transcripts.

Root cause

Third-party (Granola) hardcoded API key; unauthenticated endpoint

References