Lovable under fire over data breach

TL;DR AI
2 min readKey summary
Researchers said Lovable had a Broken Object Level Authorization flaw that let free users view other projects’ source code, credentials, and chat history with limited API requests.
Lovable first denied a breach, then said the issue stemmed from unclear public-versus-private project behavior and that it has now restricted access and fixed the problem.
The incident underscores how access-control failures in AI development tools can expose sensitive code and account data for both individual and enterprise users.



