Signal

A vibe-coding platform sat on a critical vulnerability for 48 days after closing the bug report — what founders using AI app builders need to take from it

A Broken Object Level Authorisation flaw in Lovable, the $6.6bn vibe-coding platform, let anyone with a free account read another user's source code, database credentials and customer data using five API calls — and stayed exploitable for 48 days after a researcher's HackerOne report was closed without escalation.