CVE-2025-48757

Published May 30, 2025

Last updated 5 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48757 describes a vulnerability found in the Lovable software system, specifically concerning an insufficient database Row-Level Security (RLS) policy. This flaw, present in Lovable through April 15, 2025, allows remote and unauthenticated attackers to read from or write to arbitrary database tables of sites generated using the platform. The vulnerability is categorized as an "Incorrect Authorization" issue (CWE-863) and stems from the failure to enforce or maintain secure default RLS configurations for user projects. This can lead to unauthorized access to sensitive data, including Personally Identifiable Information (PII) and API keys, and potentially enable the injection of malicious data or manipulation of existing records.

Description
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application.
Source
cve@mitre.org
NVD status
Deferred
CNA Tags
disputed, exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.3
Impact score
4.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-863

Social media

Hype score
Not currently trending
  1. CVE-2025-48757: 170 Lovable apps with no working row level security. 303 endpoints. The platform shipped a scanner that checked whether RLS existed, not whether it worked.

    @auditdpro

    14 Sept 2026

    39 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Built your app with Lovable, Bolt, Replit, or v0? A 2026 scan found 10.3% of live Lovable apps leaking user data from one missing setting (CVE-2025-48757). Free 15-min checklist to check yours: https://t.co/WmZhMNKoqx Or I'll just do the check for you, $25. https://t.co/1wsWuGBu

    @studionobleai

    10 Sept 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-48757. Of 1,645 Lovable apps analysed, 170 had databases that anyone could read. Emails, phone numbers, payment details, API keys.

    @auditdpro

    6 Sept 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Someone scanned 1,645 apps built with one AI tool. 170 had databases anyone could read — emails, phone numbers, payment details. That's CVE-2025-48757.

    @auditdpro

    30 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. I gave myself 10 minutes to break a Supabase app the same way CVE-2025-48757 broke 170+ real ones. No login. Just the public key that ships in every frontend. Here's the entire database — card numbers, password-reset links, home addresses — dumped with one curl. Plus the 3-

    @ysajang_dev

    28 Aug 2026

    14 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Most vibe-coded apps will hand a stranger their entire users table. Not an exploit. The Supabase anon key in your bundle is public by design - Row Level Security is the only thing stopping it from reading every row. With RLS off, one curl returns everything. CVE-2025-48757

    @rispectrum

    12 Jun 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 170 of 1,645 Lovable-built apps: zero database security. Anyone could read the data. Lovable's response: not our fault. CVE-2025-48757. CVSS 9.3. The AI writes the code. You own the breach.

    @sekrdcom

    30 May 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Launching Rivetz on Product Hunt tonight. The Lovable + Supabase security specialist. CVE-2025-48757 (CVSS 9.3) hit 170 production Lovable apps in a single weekend from one misconfigured setting. Fixed-price audit and fix. Every other service gives you a report and leaves.

    @JaceFromHI

    27 May 2026

    104 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CVE-2025-48757. CVSS 9.3 Critical. Lovable's default RLS configuration exposed 170+ production apps to unauthenticated database access in a single weekend. Here's exactly how the attack works, and what's in your app right now.

    @JaceFromHI

    27 May 2026

    131 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. 170 Lovable apps shipped with Supabase RLS disabled. Every table world-readable via the anon key. Emails, API keys, private rows. Anyone with DevTools could pull them. This was the default. CVE-2025-48757, CVSS 9.3. Fix: one SQL command per table. 🧵

    @rispectrum

    9 May 2026

    255 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Lovable, v0, Bolt are externalizing security costs onto users who don't know they're being externalized to. 170 RLS-disabled Lovable apps (CVE-2025-48757). 1.5M API tokens leaked from Moltbook. 18,697 student records exposed because Lovable EdTech inverted the auth check. Entire

    @rispectrum

    2 May 2026

    166 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  12. Top 5 Trending CVEs: 1 - CVE-2025-48757 2 - CVE-2026-34621 3 - CVE-2026-35616 4 - CVE-2026-23654 5 - CVE-2026-5760 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    21 Apr 2026

    254 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. A fresh warning from developer Morgan Linton says free Lovable accounts can still read other users' AI chat histories, source code, and database credentials on projects created before November 2025. The pattern is the same one that earned the platform CVE-2025-48757 last year.

    @evilsocket

    20 Apr 2026

    993 Impressions

    0 Retweets

    7 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. We published the full breakdown of CVE-2025-48757 — how 170+ Lovable apps got hacked, and the 3 lines of code that would have stopped it. https://t.co/shHDw56EUu

    @polsia

    20 Apr 2026

    141 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Atlassian just integrated Lovable into Confluence as a third-party agent. The same vibe coding platform that exposed 18K users with CVE-2025-48757 is now building prototypes from enterprise product docs. Nobody learned anything.

    @arekusandr_

    10 Apr 2026

    233 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Security researchers found 170+ Lovable-built apps leaking all their data through misconfigured Supabase. No Row-Level Security, anonymous API access to every table. It has a CVE now: CVE-2025-48757. Vibe coders keep shipping databases with the front door open.

    @arekusandr_

    1 Apr 2026

    186 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @JohnWPellew

    6 Mar 2026

    123 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @KolegaAI

    6 Mar 2026

    133 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Vibe Coding Is a Security Disaster Waiting to Happen @karpathy: "I always hit Accept All. I don't read the diffs anymore." Real incidents: Lovable: 303 insecure endpoints exposed (CVE-2025-48757) EnrichLead: $14k leaked OpenAI keys Tea app: 72k photos + 1M messages dumped to h

    @JFaganel

    6 Mar 2026

    140 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2025-48757 An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables… https://t.co/5hBWlYCs76

    @CVEnew

    30 May 2025

    513 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. [CVE-2025-48757: CRITICAL] Beware! An inadequate database security policy in Lovable website until 2025-04-15 enables unauthorized remote access to sensitive data. #cybersecurity#cve,CVE-2025-48757,#cybersecurity https://t.co/CRGGZbMgaI https://t.co/0W44SrgoK8

    @CveFindCom

    30 May 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes