4 Sources
[1]
Lovable denies data leak, cites 'intentional behavior'
Vibe-coding platform Lovable is pooh-poohing a researcher's finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the company's story keeps changing: First it attributed the publicly exposed
[2]
Lovable left AI prompts and user data exposed, one researcher found
A researcher revealed that the vibe-coding platform Lovable exposed users' chat histories with AI models to other users accessing the platform through an API (application programming interface). X user @weezerOSINT, reported the exposure in a post on Monday. "I made a Lovable account today and was
[3]
Lovable admits error in chat visibility settings, says issue fixed now - The Economic Times
Lovable, an app-building platform, has apologized for chat data exposure in public projects. The company clarified it was a mix of unclear product design and a technical error, not a data breach. Users could previously make projects public, with chat history visible. Changes were made to default
[4]
Lovable denies data breach, says public settings are 'intentional'
Lovable data breach: Stockholm-based AI app-building platform Lovable said it did not suffer a data breach after concerns surfaced over the visibility of chat messages and code in projects set to public. Stockholm-based AI app-building platform Lovable said it did not suffer a data breach after
Share
Copy Link
Stockholm-based AI app-building platform Lovable faces scrutiny after a researcher accessed sensitive user information including source code, database credentials, and AI chat histories through a simple API vulnerability. The $6.6 billion startup denies a data breach, attributing the exposure to unclear documentation and confusing public project settings.
A security vulnerability in Lovable, the Stockholm-based vibe-coding platform valued at $6.6 billion, allowed users with free accounts to access sensitive information belonging to other users, including source code, database credentials, AI chat histories, and customer data
1
. Researcher @weezerOSINT revealed on Monday that accessing this user data exposed required only five API calls from a free account, with no offensive hacking techniques needed2
. The researcher reported finding that "Lovable has a mass data breach affecting every project created before November 2025," though Lovable denies data breach claims1
.
Source: Fast Company
The data exposure stems from a Broken Object Level Authorization (BOLA) vulnerability, which occurs when an API exposes endpoints that allow users to access or modify sensitive data belonging to other users due to missing ownership validation
1
. The researcher demonstrated that making a Lovable account and conducting simple research using xAI's Grok 4.2 model took just 30 minutes, a task that would have taken hours or days before AI tools became available2
. Companies including Uber, Zendesk, and Deutsche Telekom all use Lovable's vibe coding AI tool, according to its latest funding announcement1
.Lovable's response to the security vulnerability has evolved significantly since the issue became public. Initially, the AI firm attributed the publicly exposed information to "intentional behavior" and unclear documentation, claiming that chat messages and code visibility in public projects was by design
1
. The company then shifted blame to its bug bounty partner HackerOne, stating that reports were "closed without escalation because our HackerOne partners thought that seeing public projects' chats was the intended behaviour"1
. The researcher had reported the flaw 48 days before going public, with HackerOne submission records showing a March 3 date, but Lovable labeled it a "duplicate submission" and left it open1
.
Source: The Register
Lovable explained that users could initially select either "public" or "private" options for projects, with public projects making both chat and code visible to anyone
3
. The company realized over time that many users interpreted "public" differently, assuming it applied only to published apps rather than underlying chats or development data3
. Early free-tier users had no option to create private projects and had to upgrade to paid plans for privacy features until May 2025, when Lovable started letting free-tier users make private projects1
. For enterprise customers, the ability to set visibility to public for new projects has been disabled since May 25, 2025 .
Source: ET
Related Stories
In December 2025, Lovable made all projects private by default across all tiers and "retroactively patched our API so public project chats couldn't be accessed, no matter what"
1
. However, in February, while unifying permissions in the backend, the company accidentally re-enabled access to chats on public projects1
. This technical error was what @weezerOSINT reported via the bug bounty program. Lovable acknowledged in its apology that its earlier communication "didn't properly address" the problem, clarifying that the issue was not a Lovable data breach but "a mix of unclear product design and a technical error"3
.The incident represents another example of an AI firm shirking responsibility for security flaws in its products, raising questions about accountability standards in the rapidly growing AI development tools sector
1
. Founded in 2023, Lovable raised $330 million in December at a $6.6 billion valuation, making the security vulnerability particularly concerning given the platform's scale and enterprise client base4
. The company's shifting narrative—from claiming intentional behavior to blaming unclear documentation to pointing fingers at HackerOne—highlights challenges in how startups handle security disclosures. Lovable stated it has now reversed the change and ensured that chats in public projects are no longer accessible, adding "We understand that pointing to documentation issues alone was not enough here. We'll do better"3
. HackerOne declined immediate comment, stating they need to review details carefully before responding1
.Summarized by
Navi
[1]
09 May 2026•Technology

21 Aug 2025•Technology

16 Jul 2025•Technology

1
Technology

2
Policy and Regulation

3
Technology
