21/04/2026
A researcher found 16 vulnerabilities in one Lovable-built app this week. Six critical. 18,000 users' data, exposed.
Any free account could pull every Lovable project created before November 2025: source code, database credentials, chat logs, customer data. Lovable patched new projects in March, left older ones live for 48 days, then called it "intentional" on Monday before reversing.
If your business runs on an app built by Lovable, v0, Bolt, or any other AI builder, do three things today: rotate your credentials, turn on row-level security, and get a developer to read the generated code.
That last one is our job. Kingbird audits AI-built apps and rebuilds the parts that should never have shipped. Message us here or book a review at kingbirdsolutions.com. Three audit slots open this week.