Skip to content

Lovable · 2025-05

Lovable-built apps, CVE-2025-48757

Broken access control reported across 170 production applications built with Lovable.

Last updated 2025-05
Observed

What the sources report

The sources report broken access control across 170 production applications.

Every one of them was built with Lovable.

The issue carries the identifier CVE-2025-48757.

Root cause class

Broken access control

Covered by

What ShipReady can say

When tables answer the browser key from outside, the free check observes it as O8. Whether each row rule is correct is not something a URL can read, so the rest stays Not verified.

Sources

Check your app

Run all sixteen groups on your published address and see the evidence behind every result.

Running it confirms you own this app or are authorized to test it. ShipReady reads its public pages and JavaScript bundles.

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026