Lovable-built apps, CVE-2025-48757
Broken access control reported across 170 production applications built with Lovable.
Builder
Lovable ships a hosted app with a backend behind it. It handles transport and hosting. It does not decide who may read a row.
Hosting, HTTPS and the certificate.
A deployed build on every publish.
A managed backend with authentication and storage when you enable Cloud.
Environment values kept out of the repository.
It does not decide which rows an account may read. You write those rules.
It does not stop a server key being pasted into a client file.
It does not test your sign in flow, your rollback, or your refund path.
It does not check the dependency your agent invented.
CVE-2025-48757 reported broken access control across 170 production applications built with Lovable.
A scan of 5,600 vibe-coded apps found more than 400 exposed secrets.
Fix prompts for Lovable are written for Lovable chat. They name the file to change, tell the agent to change nothing else, and end by asking for the value that was set so the check can be run again.
Lovable, Lovable Cloud, Supabase, Stripe.
Broken access control reported across 170 production applications built with Lovable.
Run the free Launch Risk Check on your app
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026