Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus
ID: 16ee1408-b212-56f1-912d-b6d95855f9e1
STIX ID: report--16ee1408-b212-56f1-912d-b6d95855f9e1
Feed Name: The Register (Security)
Threat Score
Lovable, an AI "vibe-coding" platform, had a Broken Object Level Authorization (BOLA) issue that allowed any free account to access other users' projects, including source code, database credentials and AI chat histories; a researcher reported the flaw via HackerOne, the company initially downplayed it as documentation/intentional behavior, then retroactively patched permissions and criticized the bug‑bounty triage process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
