logo

Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw

ID: 095c8ae4-183e-58e2-8988-e9bec3d5b700

STIX ID: report--095c8ae4-183e-58e2-8988-e9bec3d5b700

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-20

Date Updated: 2026-05-08

Author: Guru Baran

...
...

A Broken Object Level Authorization (BOLA) flaw in Lovable's API (notably the GetProjectMessagesOutputBody endpoint) is reportedly returning full project message histories, AI reasoning logs, and stored secrets to unauthenticated/free-tier accounts for projects created before November 2025. Researchers found exposed Supabase credentials, source code, and real user records—including data tied to nonprofit and corporate accounts—while the platform has only partially remediated new projects, leaving legacy projects at risk; users are advised to rotate keys and secrets and audit affected projects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.