Lovable platform suffers mass data breach exposing source code, database credentials, and customer data to any free account for all projects created before November 2025.
Security & Exploits ·
A security researcher disclosed that Lovable experienced a data breach affecting all projects created before November 2025, with unauthorized access available to users holding free accounts. The exposure included source code, database credentials, AI conversation histories, and customer data across affected projects.
The breach was discoverable through a straightforward test: the researcher created a free account and gained read access to another user's sensitive materials. The vulnerability affected accounts belonging to employees at major technology companies including Nvidia, Microsoft, Uber, and Spotify, according to the disclosure.
The issue had been reported to the platform 48 days prior to the public disclosure but remained unfixed at the time of reporting. The company reportedly marked the vulnerability report as a duplicate and did not resolve the underlying problem, leaving the exposure unaddressed. It remains unclear whether remediation efforts have since begun or whether affected users were notified of the breach.