Data Security, AI/ML, Vulnerability Management

Lovable AI coding platform faces scrutiny over data exposure

(Adobe Stock)

As detailed in The Register, the AI coding platform Lovable is facing criticism following a researcher's discovery of a significant security flaw. The vulnerability allowed unauthorized access to sensitive user information, including credentials, chat history, and source code, through free accounts.

A security researcher, operating under the handle @weezerOSINT, reported that a simple free account on Lovable provided access to other users' source code and database credentials. The issue stemmed from a Broken Object Level Authorization (BOLA) vulnerability, where API endpoints lacked proper ownership validation.

Lovable's initial response attributed the exposure to unclear documentation and "intentional behavior," later shifting blame to its bug bounty partner, HackerOne. The company's statements evolved, with Lovable eventually apologizing for its earlier responses and acknowledging a mistake in its permission handling that accidentally re-enabled access to public project chats.

Source: The Register

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds