Lovable · 2025-05
Lovable-built apps, CVE-2025-48757
Broken access control reported across 170 production applications built with Lovable.
Last updated 2025-05
Observed
What the sources report
The sources report broken access control across 170 production applications.
Every one of them was built with Lovable.
The issue carries the identifier CVE-2025-48757.
Root cause class
Broken access control
Covered by
What ShipReady can say
When tables answer the browser key from outside, the free check observes it as O8. Whether each row rule is correct is not something a URL can read, so the rest stays Not verified.
Sources
Check your app
Run all sixteen groups on your published address and see the evidence behind every result.
ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.
Last updated September 20, 2026
