Lovable
Disclosed Apr 20, 20265 months agoUnverified
Authorization flaw exposed chat histories of public Lovable projects
A broken object level authorization flaw in Lovable let any free-tier account read the AI chat histories of public projects; after initially calling it intentional behavior and blaming its documentation and HackerOne triage, Lovable apologized and fixed it.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Apr 20, 2026 |
| Attack | Exposed data |
| Data exposed | Prompts and chats, Source code, Credentials and tokens |
| Sector | AI · SE |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Lovable Data Leak: BOLA Vulnerability and App Security Riskshalborn.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Apr 20 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.