Skip to content

Lovable

Disclosed Apr 20, 20265 months agoUnverified

Authorization flaw exposed chat histories of public Lovable projects

A broken object level authorization flaw in Lovable let any free-tier account read the AI chat histories of public projects; after initially calling it intentional behavior and blaming its documentation and HackerOne triage, Lovable apologized and fixed it.

What is known

People affectedNot stated in the sources we have
DisclosedApr 20, 2026
AttackExposed data
Data exposedPrompts and chats, Source code, Credentials and tokens
SectorAI · SE
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalApr 20
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Lovable

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.