The app allows users to join and participate in pop-up public or private audio chatrooms, promising that conversations are not recorded and have to be experienced live.
But US cyber-security researchers tweeted that a user had found a way to stream audio to another website.
The incident occurred because a user had realized that it was possible to be in multiple chatrooms at once.
By understanding how this worked, the user could connect a Clubhouse API to his website, and essentially "share" his login remotely with anyone on the internet who wanted to listen to the audio chats from the app.
Sunday's incident comes after Clubhouse made assurances that user data couldn't be stolen by cyber-criminals or state-sponsored hackers, in response to a warning from Stanford University's Internet Observatory, which is headed by Facebook's former security chief Alex Stamos.
Stanford's cyber-security researchers discovered several security flaws, including the fact that the users' unique ID numbers and the ID numbers of the Clubhouse chatrooms they created were being transmitted in plaintext and it could be possible connect IDs to specific user profiles.