agent-postmortems a structured database of real AI-agent failures

← all incidents

incident high confidence: corroborated status: factual

Inverted access-control in AI-built Lovable apps exposed user data across 170 sites

2025-lovable-access-control-exposure · 2025-07-01

Applications generated on the Lovable vibe-coding platform shipped inverted access-control logic (CVE-2025-48757) — authenticated users were blocked while unauthenticated visitors had full read/write access — exposing user data across 170+ production apps affecting 18,000+ users. Representative of the wider vibe-coding security-debt pattern.

System

Framework
Lovable (AI app-generation platform)
Tools
code-generation, database
Vendor
Lovable
Autonomy
supervised-autonomous

Classification

Primary class
insecure-output
Chain
insecure-output/broken-authz → data-exfiltration/via-output
Attack vector
n-a
Causation
entity: ai · intentionality: unintentional · timing: pre-deployment

Trigger

Apps generated on the platform shipped access-control logic that was effectively inverted: authenticated users were blocked while unauthenticated visitors were granted access, allowing anyone to read and write user data.

Root cause

Agent-generated code produced incorrect authorization logic that was deployed without a security review capable of catching the inversion, across many apps built the same way.

Contributing factors

  • Access-control correctness was assumed rather than tested in generated apps.
  • The same flawed pattern propagated across many apps built on the platform.
  • Non-expert builders shipped generated code without a security review step.

Detection

Identified by security researchers and assigned CVE-2025-48757; reported in writeups of vibe-coding security failures.

Recovery

The platform addressed the access-control issue; affected apps required the corrected authorization logic to be applied.

Prevention

Treat agent-generated auth code as untrusted until reviewed; add automated authorization tests and security scanning to the generation pipeline; default to deny; verify row-level security and access rules before deployment.

Blast radius

Data
User data across 170+ production applications was accessible to unauthenticated visitors due to the inverted access-control logic. pii
User harm
Exposure of user data for an estimated 18,000+ users across the affected applications. economic psychological
Scope
170+ apps, 18,000+ users
Reversibility
irreversible

References

OWASP LLM
LLM02 LLM05
MITRE ATLAS
AML.T0024
Tags
vibe-coding insecure-output authorization security-debt

Sources

Cite this incident

@misc{2025-lovable-access-control-exposure,
  title = {Inverted access-control in AI-built Lovable apps exposed user data across 170 sites},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-lovable-access-control-exposure/}
}