← the record
WF-OK0FGL

Lovable security flaw exposed user data from 170 apps

Lovable, a Swedish startup, failed to fix a critical security flaw in its vibe coding service. Researchers found 170 Lovable-created web apps that exposed users' personal data, including names, emails, financial information, and API keys. Lovable acknowledged the issue and implemented a security scan, but the flaw remained unresolved.

Date it happened
2025-03-20
Organisation involved
Lovable
Product, system or model
Lovable
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from semafor.com. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.

Lovable security flaw exposed user data from 170 apps — Wayward Fowl