homeblogresumecontact

blog

Reading Anyone's Private Meta AI Conversations — Without Authentication
The sendMessageStream GraphQL mutation on meta.ai doesn't check whether you own a conversation. One API call to read anyone's full chat history.
March 2026$5,000CVSS 7.5

© 2026 luke farchione