48 days. That's how long Lovable left a broken object-level authorization bug in its API open, letting anyone with a free account pull other users’ profiles, projects, source code and embedded database credentials. The Next Web reported the April disclosure, saying the flaw was first reported to Lovable’s bug bounty on March 3 and shown publicly on April 20, and that the company patched new projects but didn't roll the fix back to older projects. Researchers and security firms say the Lovable case is one high-profile example in a string of “vibe-coded” app failures that have exposed source code, Supabase API keys, authentication tokens and thousands of personal records.

Lovable, the vibe-coding platform valued at $6.6 billion and used by roughly eight million people, suffered at least three documented security incidents that together exposed source code, database credentials, AI chat histories and the personal data of thousands of users across projects built on the service. The Next Web reported the timeline and the technical details of the primary incident.

How the Lovable flaw worked

Researchers identified a broken object-level authorization flaw, known as BOLA, in Lovable’s API. The researcher who found the bug notified Lovable’s bug bounty program on March 3, and publicly demonstrated the problem on April 20. The bug let an attacker enumerate and retrieve other users’ profiles, public projects and embedded secrets with as few as five API calls.

When the researcher followed up, Lovable marked the disclosure duplicate and closed it, according to the report. Lovable later patched the flaw for newly created projects, but it didn't apply the fix retroactively to existing projects created before November 2025. The company initially denied that a data breach had occurred, pointed to public documentation and said report handling involved its HackerOne partner, then issued a partial apology acknowledging that documentation alone was not enough.

The Next Web detailed concrete downstream consequences. Extracting a user’s source code via the API also returned hardcoded Supabase database credentials. At least one affected project belonged to the Connected Women in AI nonprofit, and the exposed records included names, job titles, LinkedIn profiles and Stripe customer IDs.

Wider pattern across vibe-coded apps

Lovable isn't an outlier.

Security researchers and industry teams have found repeatable patterns of misconfiguration and insecure defaults in so-called vibe-coded applications, which aim to speed app creation through templates and hosted services.

Wiz Security reported a security review of Moltbook, a social network built for AI agents, and found a Supabase API key embedded in client-side JavaScript. That public key granted unauthenticated read and write access to the production database, which Wiz said let an attacker access authentication tokens, email addresses and private messages. Wiz warned that without Row Level Security policies the public API key effectively becomes full database access, allowing impersonation of agents, posting as high-profile accounts and content injection.

Infosecurity Magazine relayed the concrete counts from Wiz’s Moltbook analysis: 1.5 million API authentication tokens, 30,000 email addresses and several thousand private messages were exposed. Those figures come from the Wiz-reported analysis and haven't been independently verified by other publications, according to the reporting.

Wiz Research published a broader study of vibe-coded applications and found a high incidence of simple but critical mistakes. Examples include authentication logic implemented entirely in client-side JavaScript, hardcoded passwords visible in shipped code, and missing Row Level Security on hosted Supabase instances. Wiz Research summarized that one in five organizations is building on these rapid-deploy platforms, and that many of the discovered issues are preventable with basic configuration and code review.

Across multiple incidents the technical themes repeat. Developer-facing ease of deployment, combined with default or poorly documented templates, leads teams to ship apps that expose secrets in client code or in project files. Managed database services such as Supabase are frequently used without RLS or proper token scoping, which can turn public keys into full database credentials.

The organizational consequences are tangible. Researchers flagged accounts tied to employees at large companies in the Lovable dataset. The Moltbook design allowed automated creation of millions of agents and 17,000 registered human owners, which multiplies the scale of potential abuse if credentials are exposed.

The reporting also contains single-source claims that deserve caution. The Next Web reported industry-wide figures such as 40-62% of AI-generated code containing vulnerabilities and that 91.5% of vibe-coded apps had at least one hallucination-related flaw in Q1 2026.

This projection that 60% of all new code will be AI-generated by year end also appears only in The Next Web piece. Those numbers haven't been corroborated across the other reports.

Industry teams have published remediation guidance. Wiz and Wiz Research released advice for developers and organizations using vibe-coding tools, focusing on enforcing Row Level Security, removing secrets from client-side code, and tightening token scopes. Still, the sources didn't identify any industry-wide remediation deadline or coordinated disclosure schedule.

Companies that build on low-friction platforms face a trade-off. Rapid prototyping and template reuse accelerate delivery.

But when templates ship with example credentials or when authentication checks live in browser-delivered files, the convenience becomes a security liability. Several of the incidents involved hardcoded Supabase credentials visible in source code or in returned project files, which allows an attacker to move from discovery to full database access in short order.

For organizations that rely on Supabase and similar managed services, applying RLS, scoping keys to minimal privileges and removing secrets from client-facing bundles are the first lines of defense. Researchers said these steps are basic yet widely neglected across the sampled vibe-coded apps.

Related Articles

As of reporting, Lovable had patched new projects but not retroactively fixed older projects, and the bug bounty timeline began on March 3. Wiz and Wiz Research have published remediation guidance, but no coordinated industry deadline for fixes was specified.

This article was created with AI assistance.