https://shipreadyai.dev/builders/lovable

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Lovable

Lovable ships a hosted app with a backend behind it. It handles transport and hosting. It does not decide who may read a row.

## What the builder handles for you

Hosting, HTTPS and the certificate.
A deployed build on every publish.
A managed backend with authentication and storage when you enable Cloud.
Environment values kept out of the repository.

## What it does not

It does not decide which rows an account may read. You write those rules.
It does not stop a server key being pasted into a client file.
It does not test your sign in flow, your rollback, or your refund path.
It does not check the dependency your agent invented.

## Incidents involving it

CVE-2025-48757 reported broken access control across 170 production applications built with Lovable.
A scan of 5,600 vibe-coded apps found more than 400 exposed secrets.

## The fix prompt dialect

Fix prompts for Lovable are written for Lovable chat. They name the file to change, tell the agent to change nothing else, and end by asking for the value that was set so the check can be run again.

## Stack checklists that apply

Lovable, Lovable Cloud, Supabase, Stripe.
