CVE-2025-48757

Published May 30, 2025

Last updated 2 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48757 describes a vulnerability found in the Lovable software system, specifically concerning an insufficient database Row-Level Security (RLS) policy. This flaw, present in Lovable through April 15, 2025, allows remote and unauthenticated attackers to read from or write to arbitrary database tables of sites generated using the platform. The vulnerability is categorized as an "Incorrect Authorization" issue (CWE-863) and stems from the failure to enforce or maintain secure default RLS configurations for user projects. This can lead to unauthorized access to sensitive data, including Personally Identifiable Information (PII) and API keys, and potentially enable the injection of malicious data or manipulation of existing records.

Description
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application.
Source
cve@mitre.org
NVD status
Deferred
CNA Tags
disputed, exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.3
Impact score
4.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-863

Social media

Hype score
Not currently trending
  1. 170 of 1,645 Lovable-built apps: zero database security. Anyone could read the data. Lovable's response: not our fault. CVE-2025-48757. CVSS 9.3. The AI writes the code. You own the breach.

    @sekrdcom

    30 May 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. Launching Rivetz on Product Hunt tonight. The Lovable + Supabase security specialist. CVE-2025-48757 (CVSS 9.3) hit 170 production Lovable apps in a single weekend from one misconfigured setting. Fixed-price audit and fix. Every other service gives you a report and leaves.

    @JaceFromHI

    27 May 2026

    104 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-48757. CVSS 9.3 Critical. Lovable's default RLS configuration exposed 170+ production apps to unauthenticated database access in a single weekend. Here's exactly how the attack works, and what's in your app right now.

    @JaceFromHI

    27 May 2026

    131 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 170 Lovable apps shipped with Supabase RLS disabled. Every table world-readable via the anon key. Emails, API keys, private rows. Anyone with DevTools could pull them. This was the default. CVE-2025-48757, CVSS 9.3. Fix: one SQL command per table. 🧵

    @rispectrum

    9 May 2026

    255 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Lovable, v0, Bolt are externalizing security costs onto users who don't know they're being externalized to. 170 RLS-disabled Lovable apps (CVE-2025-48757). 1.5M API tokens leaked from Moltbook. 18,697 student records exposed because Lovable EdTech inverted the auth check. Entire

    @rispectrum

    2 May 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Top 5 Trending CVEs: 1 - CVE-2025-48757 2 - CVE-2026-34621 3 - CVE-2026-35616 4 - CVE-2026-23654 5 - CVE-2026-5760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    21 Apr 2026

    254 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. A fresh warning from developer Morgan Linton says free Lovable accounts can still read other users' AI chat histories, source code, and database credentials on projects created before November 2025. The pattern is the same one that earned the platform CVE-2025-48757 last year.

    @evilsocket

    20 Apr 2026

    993 Impressions

    0 Retweets

    7 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. We published the full breakdown of CVE-2025-48757 — how 170+ Lovable apps got hacked, and the 3 lines of code that would have stopped it. https://t.co/shHDw56EUu

    @polsia

    20 Apr 2026

    141 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Atlassian just integrated Lovable into Confluence as a third-party agent. The same vibe coding platform that exposed 18K users with CVE-2025-48757 is now building prototypes from enterprise product docs. Nobody learned anything.

    @arekusandr_

    10 Apr 2026

    233 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Security researchers found 170+ Lovable-built apps leaking all their data through misconfigured Supabase. No Row-Level Security, anonymous API access to every table. It has a CVE now: CVE-2025-48757. Vibe coders keep shipping databases with the front door open.

    @arekusandr_

    1 Apr 2026

    186 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @JohnWPellew

    6 Mar 2026

    123 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @KolegaAI

    6 Mar 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @JFaganel

    6 Mar 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2025-48757 An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables… https://t.co/5hBWlYCs76

    @CVEnew

    30 May 2025

    513 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. [CVE-2025-48757: CRITICAL] Beware! An inadequate database security policy in Lovable website until 2025-04-15 enables unauthorized remote access to sensitive data. #cybersecurity#cve,CVE-2025-48757,#cybersecurity https://t.co/CRGGZbMgaI https://t.co/0W44SrgoK8

    @CveFindCom

    30 May 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes