Mark RadarMARK RADAR
EN

Lovable Security Flaw Let Free Accounts Access Other Users’ Project Source Code

1 reports · First detected 2026-04-22 · Last active 2026-04-22

Swedish AI software-development startup Lovable uses natural-language prompts to generate software rapidly and is part of the emerging wave of “vibe coding” tools. Such platforms centrally store source code, AI conversations and customer data. A failure in access controls can therefore jeopardize corporate secrets and highlight the risks of prioritizing development convenience over secure design.

A recently disclosed vulnerability allowed Lovable free-account holders to access any project created by another user before November 2025, potentially exposing project source code, AI conversation histories and customer data. Lovable has fixed the flaw and publicly apologized, but the incident has prompted cybersecurity experts to question the default permissions and data-isolation mechanisms used by AI development tools.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR