https://shipreadyai.dev/incidents/lovable-cve-2025-48757

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Lovable-built apps, CVE-2025-48757

2025-05. Lovable.

## What happened

The sources report broken access control across 170 production applications.
Every one of them was built with Lovable.
The issue carries the identifier CVE-2025-48757.

## What ShipReady can say

When tables answer the browser key from outside, the free check observes it as O8. Whether each row rule is correct is not something a URL can read, so the rest stays Not verified.

## Sources

- [Cloud Security Alliance research note](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/CSA_research_note_ai_codegen_vulnerability_debt_20260406-csa-styled.pdf)
- [getautonoma vibe coding failures](https://getautonoma.com/blog/vibe-coding-failures)
