Original Reddit post

Lovable is a $6.6B vibe coding platform. They showcase apps on their site as success stories. I tested one — an EdTech app with 100K+ views on their showcase, real users from UC Berkeley, UC Davis, and schools across Europe, Africa, and Asia. Found 16 security vulnerabilities in a few hours. 6 critical. The auth logic was literally backwards — it blocked logged-in users and let anonymous ones through. Classic AI-generated code that “works” but was never reviewed. What was exposed: 18,697 user records (names, emails, roles) — no auth needed Account deletion via single API call — no auth Student grades modifiable — no auth Bulk email sending — no auth Enterprise org data from 14 institutions I reported it to Lovable. They closed the ticket. submitted by /u/VolodsTaimi

Originally posted by u/VolodsTaimi on r/ClaudeCode