AI description
CVE-2025-48757 describes a vulnerability found in the Lovable software system, specifically concerning an insufficient database Row-Level Security (RLS) policy. This flaw, present in Lovable through April 15, 2025, allows remote and unauthenticated attackers to read from or write to arbitrary database tables of sites generated using the platform. The vulnerability is categorized as an "Incorrect Authorization" issue (CWE-863) and stems from the failure to enforce or maintain secure default RLS configurations for user projects. This can lead to unauthorized access to sensitive data, including Personally Identifiable Information (PII) and API keys, and potentially enable the injection of malicious data or manipulation of existing records.
- Description
- An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application.
- Source
- cve@mitre.org
- NVD status
- Deferred
- CNA Tags
- disputed, exclusively-hosted-service
CVSS 3.1
- Type
- Secondary
- Base score
- 9.3
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- Severity
- CRITICAL
- cve@mitre.org
- CWE-863
- Hype score
- Not currently trending
170 of 1,645 Lovable-built apps: zero database security. Anyone could read the data. Lovable's response: not our fault. CVE-2025-48757. CVSS 9.3. The AI writes the code. You own the breach.
@sekrdcom
30 May 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Launching Rivetz on Product Hunt tonight. The Lovable + Supabase security specialist. CVE-2025-48757 (CVSS 9.3) hit 170 production Lovable apps in a single weekend from one misconfigured setting. Fixed-price audit and fix. Every other service gives you a report and leaves.
@JaceFromHI
27 May 2026
104 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-48757. CVSS 9.3 Critical. Lovable's default RLS configuration exposed 170+ production apps to unauthenticated database access in a single weekend. Here's exactly how the attack works, and what's in your app right now.
@JaceFromHI
27 May 2026
131 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
170 Lovable apps shipped with Supabase RLS disabled. Every table world-readable via the anon key. Emails, API keys, private rows. Anyone with DevTools could pull them. This was the default. CVE-2025-48757, CVSS 9.3. Fix: one SQL command per table. 🧵
@rispectrum
9 May 2026
255 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Lovable, v0, Bolt are externalizing security costs onto users who don't know they're being externalized to. 170 RLS-disabled Lovable apps (CVE-2025-48757). 1.5M API tokens leaked from Moltbook. 18,697 student records exposed because Lovable EdTech inverted the auth check. Entire
@rispectrum
2 May 2026
166 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2025-48757 2 - CVE-2026-34621 3 - CVE-2026-35616 4 - CVE-2026-23654 5 - CVE-2026-5760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
21 Apr 2026
254 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
A fresh warning from developer Morgan Linton says free Lovable accounts can still read other users' AI chat histories, source code, and database credentials on projects created before November 2025. The pattern is the same one that earned the platform CVE-2025-48757 last year.
@evilsocket
20 Apr 2026
993 Impressions
0 Retweets
7 Likes
0 Bookmarks
1 Reply
0 Quotes
We published the full breakdown of CVE-2025-48757 — how 170+ Lovable apps got hacked, and the 3 lines of code that would have stopped it. https://t.co/shHDw56EUu
@polsia
20 Apr 2026
141 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Atlassian just integrated Lovable into Confluence as a third-party agent. The same vibe coding platform that exposed 18K users with CVE-2025-48757 is now building prototypes from enterprise product docs. Nobody learned anything.
@arekusandr_
10 Apr 2026
233 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Security researchers found 170+ Lovable-built apps leaking all their data through misconfigured Supabase. No Row-Level Security, anonymous API access to every table. It has a CVE now: CVE-2025-48757. Vibe coders keep shipping databases with the front door open.
@arekusandr_
1 Apr 2026
186 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h
@JohnWPellew
6 Mar 2026
123 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h
@KolegaAI
6 Mar 2026
133 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h
@JFaganel
6 Mar 2026
140 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-48757 An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables… https://t.co/5hBWlYCs76
@CVEnew
30 May 2025
513 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-48757: CRITICAL] Beware! An inadequate database security policy in Lovable website until 2025-04-15 enables unauthorized remote access to sensitive data. #cybersecurity#cve,CVE-2025-48757,#cybersecurity https://t.co/CRGGZbMgaI https://t.co/0W44SrgoK8
@CveFindCom
30 May 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes