Fiverr, the $2+ billion gig work platform competing with Upwork, left customer work files publicly accessible through a misconfiguration of Cloudinary, a widely-used image and video processing service. The discovery, reported on Hacker News, revealed that files uploaded through Fiverr's messaging system—including PDFs, design files, and other client deliverables—were not only served directly to the web but indexed and searchable without authentication. Cloudinary is typically used for adding value-added processing like compression, format conversion, and optimization, but in this case, it effectively functioned as a public file storage system similar to exposed AWS S3 buckets. The incident echoes a pattern of misconfigured cloud storage that has plagued major platforms for years, from Capital One's 2019 S3 breach affecting 100 million users to countless smaller exposures involving Elasticsearch and MongoDB instances left without password protection.