https://shipreadyai.dev/incidents/tea-app-second-breach

> Discover all available pages from the documentation index at https://shipreadyai.dev/llms.txt

# Tea app, second breach

2025-07. Firebase.

## What happened

The sources report a second exposure three days after the first.
Over a million private messages were exposed.
The endpoint that served them performed no access control.

## What ShipReady can say

An endpoint that answers without checking who is asking is only visible from inside the app. This stays Not verified until auth flows and tenant isolation are reviewed.

## Sources

- [Cloud Security Alliance research note](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/CSA_research_note_ai_codegen_vulnerability_debt_20260406-csa-styled.pdf)
- [CatDoes vibe coding security checklist](https://catdoes.com/blog/vibe-coding-security-checklist)
