Full Breakdown
Lovable Platform Faces Scrutiny Over App Security Vulnerabilities
2/28/2026, 11:21:57 AM
Overview of Security Flaws
The Vibe-coding platform Lovable is under scrutiny for hosting applications with significant security vulnerabilities. Taimur Khan, a tech entrepreneur, identified 16 vulnerabilities in one Lovable-hosted app, six of which he categorized as critical. This app, which had over 100,000 views and was featured on Lovable's Discover page, leaked data of nearly 18,700 users, including 4,538 student accounts and 10,505 enterprise users. The vulnerabilities stem from the platform's reliance on Supabase for backend services, which, if not properly configured, can lead to severe security lapses.
Technical Details of Vulnerabilities
Khan highlighted that the AI-generated code for the Supabase backend often lacks essential security features, such as row-level security and role-based access. A notable flaw involved an authentication function that inadvertently blocked all authenticated users while allowing unauthenticated users access. This misconfiguration could enable attackers to access sensitive user records, send bulk emails, delete accounts, and manipulate grades, posing a significant risk to users, including minors from K-12 institutions.
Broader Implications of Vibe Coding
The issues with Lovable's platform reflect a wider trend in the software development landscape, particularly concerning Vibe coding, which was named Collins Dictionary's Word of the Year for 2025. While Vibe coding aims to democratize app development, it has also led to a proliferation of applications with inherent security flaws. A report by Veracode indicated that 45% of AI-generated code contains security vulnerabilities, raising concerns about the reliability of such technologies.
Official Statements & Responses
In response to Khan's findings, Lovable's Chief Information Security Officer, Igor Andriushchenko, stated that the company takes security concerns seriously and had contacted the app's owner to address the issues. He emphasized that Lovable conducts a free security scan for all projects before publication, which provides recommendations for addressing vulnerabilities. However, he noted that the implementation of these recommendations is ultimately the user's responsibility. Regarding Khan's report, Andriushchenko mentioned that the company only received a formal disclosure on February 26 and acted swiftly upon it.
Criticism & Opposition
Khan criticized Lovable for its lack of accountability, particularly after his report was closed without a response. He argued that if Lovable promotes itself as a platform capable of generating production-ready apps, it should also bear responsibility for the security of those applications. "You can't showcase an app to 100,000 people, host it on your own infrastructure, and then close the ticket when someone tells you it's leaking user data," Khan stated.
Conflicting Reports & Gaps
While Lovable asserts that it conducts security scans and provides recommendations, Khan's experience suggests a gap in the platform's accountability and user support. The discrepancy between Lovable's claims and Khan's experience raises questions about the effectiveness of their security protocols and user communication.
What's Next
As the creator of the vulnerable app works to rectify the identified issues, the situation underscores the need for enhanced security measures in platforms that leverage AI for app development. The ongoing dialogue about accountability in Vibe coding will likely continue as more vulnerabilities come to light.
