Lovable Security Flaw Let Free Accounts Access Other Users’ Project Source Code
Swedish AI software-development startup Lovable uses natural-language prompts to generate software rapidly and is part of the emerging wave of “vibe coding” tools. Such platforms centrally store source code, AI conversations and customer data. A failure in access controls can therefore jeopardize corporate secrets and highlight the risks of prioritizing development convenience over secure design.
A recently disclosed vulnerability allowed Lovable free-account holders to access any project created by another user before November 2025, potentially exposing project source code, AI conversation histories and customer data. Lovable has fixed the flaw and publicly apologized, but the incident has prompted cybersecurity experts to question the default permissions and data-isolation mechanisms used by AI development tools.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.