https://shipreadyai.dev/incidents/tea-app-first-breach

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Tea app, first breach

2025-07. Firebase.

## What happened

The sources report an unprotected Firebase storage instance.
Tens of thousands of user images were exposed.
The exposed files included government-issued identity documents.

## What ShipReady can say

A check from outside reads what a visitor can reach. Storage rules sit behind the app, so this one stays Not verified until a Launch Review looks at the bucket policies.

## Sources

- [Cloud Security Alliance research note](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/CSA_research_note_ai_codegen_vulnerability_debt_20260406-csa-styled.pdf)
- [CatDoes vibe coding security checklist](https://catdoes.com/blog/vibe-coding-security-checklist)
