https://www.theregister.com/2026/02/27/lovable_app_vulnerabilities/ # # Sign in / up The Register # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Agentic AI The Future of the Datacenter AWS Re:invent SC25 Supercomputing Month Cloud Infrastructure Month Datacenter Networking Nexus The State of Storage European Supercomputing AI Infrastructure Month Spotlight on RSAC AI Software Development Week Disaster Recovery Week Nvidia GTC Ransomware in Focus Cybersecurity Month VMware Explore Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Money Movement Hub HERE and AWS Guidewire InsuranceNow ZTE Nutanix: Scale Kubernetes. Not Chaos. AWS Global Partner Security Initiative Amazon Web Services (AWS) New Horizon in Cloud Computing (X) Resources Resources Whitepapers Webinars & Events Newsletters [applicatio] Applications 3 comment bubble on white Lovable-hosted app littered with basic flaws exposed 18K users, researcher claims 3 comment bubble on white Who's to blame - the vibey platforms or the humans who ignore security warnings? icon Connor Jones Fri 27 Feb 2026 // 16:36 UTC # Vibe-coding platform Lovable has been accused of hosting apps riddled with vulnerabilities after saying users are responsible for addressing security issues flagged before publishing. Taimur Khan, a tech entrepreneur with a background in software engineering, found 16 vulnerabilities - six of which he said were critical - in a single Lovable-hosted app that leaked more than 18,000 people's data. He declined to name the app during the disclosure process, although it was hosted on Lovable's platform and showcased on its Discover page. The app had more than 100,000 views and around 400 upvotes at the time Khan began his probe. [applicatio] The main issue, Khan said, was that all apps that are vibe-coded on Lovable's platform are shipped with their backends powered by Supabase, which handles authentication, file storage, and real-time updates through a PostgreSQL database connection. [applicatio] [applicatio] However, when the developer - in this case AI - or the human project owner fails to explicitly implement crucial security features like Supabase's row-level security and role-based access, code will be generated that looks functional but in reality is flawed. One example of this was a malformed authentication function. The AI that vibe-coded the Supabase backend, which uses remote procedure calls, implemented it with flawed access control logic, essentially blocking authenticated users and allowing access to unauthenticated users. [applicatio] Khan said the intent was to block non-admins from accessing parts of the app, but the faulty implementation blocked all logged-in users - an error he said was repeated across multiple critical functions. "This is backwards," said Khan. "The guard blocks the people it should allow and allows the people it should block. A classic logic inversion that a human security reviewer would catch in seconds - but an AI code generator, optimizing for 'code that works,' produced and deployed to production." Because the app itself was a platform for creating exam questions and viewing grades, the userbase is naturally comprised of teachers and students. Some were from top US universities such as UC Berkeley and UC Davis, while there were "K-12 institutions with minors likely on the platform" as well, Khan said. [applicatio] With the security flaws in place, an unauthenticated attacker could trivially access every user record, send bulk emails through the platform, delete any user account, grade student test submissions, and access organizations' admin emails, for example. Of the 18,697 total user records exposed, 14,928 contained unique email addresses. The dataset included 4,538 student accounts - all with email addresses - 10,505 enterprise users, and 870 users whose full PII was exposed. The security flaws here are not exclusive to apps hosted by Lovable; the issue is broader and well-told by now. Vibe coding, Collins Dictionary's Word of the Year for 2025, promised to break down software development's steep learning curve and empower any prompt jockey to bring their app ideas to life. However, when AI isn't generating slop bug reports in pursuit of lucrative bug bounties or catastrophically forgoing instructions, it can be found spewing glitzy-looking apps laden with vulnerabilities. * Bcachefs creator insists his custom LLM is female and 'fully conscious' * IBM stock dives after Anthropic points out AI can rewrite COBOL fast * Amazon's vibe-coding tool Kiro reportedly vibed too hard and brought down AWS * Agile Manifesto turns 25 - just in time for vibe coding to test it Veracode, for instance, recently found that 45 percent of AI-generated code contained security flaws, not to mention the myriad tales of woe reported by The Register in recent months. Khan said he believes Lovable should take responsibility for the security of the apps it hosts, and was especially peeved when, after reporting his findings via company support, his ticket was reportedly closed without response. "If Lovable is going to market itself as a platform that generates production-ready apps with authentication 'included,' it bears some responsibility for the security posture of the apps it generates and promotes," Khan said. "You can't showcase an app to 100,000 people, host it on your own infrastructure, and then close the ticket when someone tells you it's leaking user data. At minimum, a basic security scan of showcased applications would have caught every critical finding in this report." Lovable told The Register that the company has contacted the owner of the app in question and takes "any findings of this kind extremely seriously." Regarding the closed ticket, Lovable CISO Igor Andriushchenko said that the company only received "a proper disclosure report" on the evening of February 26 and acted on the findings "within minutes." "Any project built with Lovable includes a free security scan before publishing," Andriushchenko told The Register. "This scan checks for vulnerabilities and, if found, provides recommendations on actions to take to resolve before publishing. "Ultimately, it is at the discretion of the user to implement these recommendations. In this case, that implementation did not happen. "This project also includes code not generated by Lovable and the vulnerable database is not hosted by Lovable. We have been in contact with the creator of the app, who is now addressing the issue." (r) Get our Tech Resources # Share More about * AI * Cybersecurity * Software More like these x More about * AI * Cybersecurity * Software Narrower topics * AdBlock Plus * AIOps * App * Application Delivery Controller * Audacity * Center for Internet Security * Confluence * Database * DeepSeek * FOSDEM * FOSS * Gemini * Google AI * GPT-3 * GPT-4 * Grab * Graphics Interchange Format * IDE * Image compression * Jenkins * Large Language Model * Legacy Technology * LibreOffice * Machine Learning * Map * MCubed * Microsoft 365 * Microsoft Office * Microsoft Teams * Mobile Device Management * Neural Networks * NLP * OpenOffice * Programming Language * QR code * Retrieval Augmented Generation * Retro computing * RSA Conference * Search Engine * Software Bill of Materials * Software bug * Software License * Star Wars * Tensor Processing Unit * Text Editor * TOPS * User interface * Visual Studio * Visual Studio Code * WebAssembly * Web Browser * WordPress * Zero trust Broader topics * Security * Self-driving Car More about # Share 3 comment bubble on white COMMENTS More about * AI * Cybersecurity * Software More like these x More about * AI * Cybersecurity * Software Narrower topics * AdBlock Plus * AIOps * App * Application Delivery Controller * Audacity * Center for Internet Security * Confluence * Database * DeepSeek * FOSDEM * FOSS * Gemini * Google AI * GPT-3 * GPT-4 * Grab * Graphics Interchange Format * IDE * Image compression * Jenkins * Large Language Model * Legacy Technology * LibreOffice * Machine Learning * Map * MCubed * Microsoft 365 * Microsoft Office * Microsoft Teams * Mobile Device Management * Neural Networks * NLP * OpenOffice * Programming Language * QR code * Retrieval Augmented Generation * Retro computing * RSA Conference * Search Engine * Software Bill of Materials * Software bug * Software License * Star Wars * Tensor Processing Unit * Text Editor * TOPS * User interface * Visual Studio * Visual Studio Code * WebAssembly * Web Browser * WordPress * Zero trust Broader topics * Security * Self-driving Car TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Double whammy: Steaelite RAT bundles data theft, ransomware in one evil tool Credential and cryptocurrency theft, live surveillance, ransomware - an attacker's Swiss Army knife Cyber-crime27 Feb 2026 | Trump orders purge of 'woke' Anthropic from government updated Without a single 'You're Fired' joke Public Sector27 Feb 2026 | PCs and phones to get more boring and expensive in 2026 thanks to memory drought 'This is perhaps the biggest challenge the industry has faced since its inception' Systems27 Feb 2026 | 5 Why high-performance Java is becoming a business imperative A new generation of JVM technologies is reshaping how businesses build, deploy, and scale mission-critical Java applications. Sponsored Feature [applicatio] Amazon and Nvidia open their wallets to lock in OpenAI's business while SoftBank keeps the lights on ChatGPT maker announces $110B in new investment amid flurry of self-serving deals AI + ML27 Feb 2026 | 6 Suspected Nork digital intruders caught breaking into US healthcare, education orgs Who is knocking at the Dohdoor? Cyber-crime27 Feb 2026 | Oak Ridge spawns institute to curb AI datacenter power surge Lab aims to link power, cooling, and workload management to ease strain on the US grid Systems27 Feb 2026 | 1 Microsoft HoloLens finds second home in the military after failing battlefield tests Let's hope air cargo checks don't trigger the same headaches Public Sector27 Feb 2026 | 2 Harvard boffins finally crack the mystery of squeaky sneakers Are they shoe-ins for an award? Hard to say Offbeat27 Feb 2026 | 3 Ransomware payments cratered in 2025, but attacks surged to record highs Smaller crews piled in as old names splintered and rebranded Research27 Feb 2026 | 2 French DIY etailer ManoMano admits customer data stolen Crooks claim they helped themselves to over 37M accounts during January hit on subcontractor Cyber-crime27 Feb 2026 | 4 Japan's Rapidus lands $1.7B to chase 2nm chip production by 2027 Government and 32 private-sector backers fund push to take on TSMC and Samsung at leading-edge nodes Systems27 Feb 2026 | The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2025 no-js