Lovable
Incident posture
Timeline
Summary
Lovable faced a security issue after an X user claimed that, using a free account, they could view other users' code, AI chat histories, and customer data from projects created before a certain point. The company initially said that access to public project code was intentional but later acknowledged the setting was a mistake and restored private chats for public projects. Critics called the first response gaslighting, while some users appreciated the eventual transparency. Security experts noted the incident highlights risks of inadequate defaults and threat modeling in AI‑assisted coding tools.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday, an X user named Impulsive accused Lovable of a mass data breach affecting every project created before November 2025, stating they could access another user's code, AI chat histories, and customer data through a free Lovable account. The user said that employees from Nvidia, Microsoft, Uber, and Spotify all have accounts on the platform. They added that the bug had been reported 48 days earlier, was marked as duplicate, and left unfixed.
Lovable initially denied that a data breach had occurred, claiming that viewing public projects' code was a deliberate design choice. After public backlash, the company issued a second statement explaining that it had allowed public project visibility to let users explore others' work but had turned the feature off by default in December. Lovable acknowledged the security error and reverted the setting so that all public projects' chats are now private again. Some users praised the company's transparency, while others criticized the first response as gaslighting.
The Lovable incident follows a leak by Anthropic in late March that exposed an archive of nearly 2,000 files and 500,000 lines of code. Earlier the same week, Vercel reported an incident that gave unauthorized users access to certain internal systems. Anish Acharya, a general partner at Andreessen Horowitz, warned companies not to rely on AI‑assisted coding for every part of their business because of the associated risks. Professional developers generally discourage overreliance on AI, noting that it can produce messy, untested code and that vibe coding raises information‑security concerns such as the exposure of company data. Tom Van de Wiele, founder of Hacker Minded, described the episode as another example of lacking secure defaults and a failure to threat‑model for the automated and AI age. Jake Moore, global cybersecurity advisor at ESET, said that arguing over whether the event qualifies as a traditional breach distracts from the larger point that it is not harmless, even if it is not a classic breach.
Sources
Sources available to members: 1 source.