Close Menu
    Facebook X (Twitter) Instagram
    TRENDING :
    • Why Gen Z Is Choosing to Stay At Home Instead of Dating
    • Heavily Armed Suspect Arrested at Trump National Golf Course Ahead of President’s Visit * The Gateway Pundit * by Cristina Laila
    • How Motherhood Is Redefining Leadership for Women Founders
    • Revealed: Here’s What Pirro Brought to the White House After Trump Blasted Her For Dropping Reflecting Pool Criminal Case
    • SpaceX posts strong revenue in first earnings report since IPO
    • Football National Champion Breiden Fehoko Slams (W)NBA Brass Over Nonsense Trans Comments – “Stop Pushing that Bulls**t on This Generation. It’s Only Groomer Parents”
    • Flo Rida Becomes Equity Partner in Beyond Juicery + Eatery
    • Young Woman Shares Distrubing Details of Child Migrant Program Under Biden’s HHS Secretary Xavier Becerra She Says Led Her Straight Into the Hands of Child Traffickers
    Populist Bulletin
    • Home
    • US Politics
    • World Politics
    • Economy
    • Business
    • Headline News
    Populist Bulletin
    Home»Business»Lovable left AI prompts and user data exposed, one researcher found
    Business 4 Mins Read

    Lovable left AI prompts and user data exposed, one researcher found

    Business 4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A researcher revealed that the vibe-coding platform Lovable exposed users’ chat histories with AI models to other users accessing the platform through an API (application programming interface).

    X user @weezerOSINT, reported the exposure in a post on Monday. “I made a Lovable account today and was able to access another user’s source code, database credentials, AI chat histories, and customer data are all readable by any free account,” the researcher wrote. The post included a screenshot of another Lovable user’s project code and chats, along with an unresolved ticket for the bug that allegedly caused the data leak.

    Lovable has a mass data breach affecting every project created before november 2025.
    I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account.
    nvidia,… pic.twitter.com/QcVvz9cNZl

    — impulsive (@weezerOSINT) April 20, 2026

    In a follow-up conversation with Fast Company, @weezerOSINT (who did not share his real name) says it took 30 minutes using xAI’s Grok 4.2 model to conduct the research, adding that before AI, finding similar exposures would take hours or days.

    @weezerOSINT reported the issue via HackerOne, a cybersecurity company that runs bug bounty and vulnerability disclosure programs, in early March. On Monday, the researcher showed that Lovable projects created before November 2025 still expose the data.

    Lovable declined to provide an executive to explain the situation, and pointed to its public statement on X.

    Lovable initially said on X that no “data breach” had occurred, and that exposing project code was “intentional behavior.” When users mark their projects “public,” the company explained, they opt to have their code visible to other users.

    We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings.
    To be clear: We did not suffer a data breach.
    Our documentation of what “public” implies was unclear, and that’s a failure on us.
    Specifically…

    — Lovable (@Lovable) April 20, 2026

    But that did not account for the exposure of users’ chats and prompts with the AI model, which Lovable made accessible for public projects until recently.

    “We also retroactively patched our API so public project chats couldn’t be accessed, no matter what,” Lovable said in a second, clarifying post on X. “Unfortunately, in February, while unifying permissions in our backend, we accidentally re-enabled access to chats on public projects.”

    We’re sorry our initial statement didn't properly address our mistake. Here's what a public project on Lovable means, and how we got to where we are today:
    In the early days, people didn't know what Lovable was capable of. So we wanted to make it easy to explore what others were… https://t.co/8X2LMjETaS

    — Lovable (@Lovable) April 20, 2026

    As for @weezerOSINT’s early-March report to HackerOne, Lovable says the ticket had been closed because its “HackerOne partners” believed that viewing public projects’ chats was “the intended behavior.”

    As a vibe-coding platform, Lovable treats natural-language prompts used to generate code as a core part of the building process. The company initially believed its community would benefit from seeing how other developers used prompts to build features, functions, components, or database schemas, so chats were treated as standard project metadata.

    But the risk of exposing sensitive information in those chat histories appears to have outweighed that benefit. Lovable says that in December 2025 it made all new projects “private by default” for all users.

    Lovable’s most recent funding round came in December 2025, when it raised $330 million from CapitalG, Menlo Ventures, Khosla Ventures, and others. After the round, the company was valued at $6.6 billion, reportedly tripling its valuation in about five months.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Why Gen Z Is Choosing to Stay At Home Instead of Dating

    August 5, 2026

    How Motherhood Is Redefining Leadership for Women Founders

    August 4, 2026

    SpaceX posts strong revenue in first earnings report since IPO

    August 4, 2026
    Top News
    Economy 3 Mins Read

    Trade Between India And China Soars

    Economy 3 Mins Read

    India’s imports from China reached a record $79.41 billion during the first six months of…

    Eric Adams drops out of the New York City mayoral race. Here’s why

    September 29, 2025

    How ‘slop’ became the defining word of 2025

    December 15, 2025

    War Is Now Appearing In Inflation Data

    June 11, 2026
    Top Trending
    Business 4 Mins Read

    Why Gen Z Is Choosing to Stay At Home Instead of Dating

    Business 4 Mins Read

    Key Takeaways Dating has become a financial luxury for Gen Z and…

    World Politics 3 Mins Read

    Heavily Armed Suspect Arrested at Trump National Golf Course Ahead of President’s Visit * The Gateway Pundit * by Cristina Laila

    World Politics 3 Mins Read

    A heavily armed man was arrested on Sunday near Trump National Golf…

    Business 7 Mins Read

    How Motherhood Is Redefining Leadership for Women Founders

    Business 7 Mins Read

    Opinions expressed by Entrepreneur contributors are their own. Key Takeaways As leaders,…

    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    About us

    The Populist Bulletin was founded with a fervent commitment to inform, inspire, empower and spark meaningful conversations about the economy, business, politics, government accountability, globalization, and the preservation of American cultural heritage.

    We are devoted to delivering straightforward, unfiltered, compelling, relatable stories that resonate with the majority of the American public, while boldly challenging false mainstream narratives that seem to only serve entrenched elitists, and foreign interests.

    Top Picks

    Why Gen Z Is Choosing to Stay At Home Instead of Dating

    August 5, 2026

    Heavily Armed Suspect Arrested at Trump National Golf Course Ahead of President’s Visit * The Gateway Pundit * by Cristina Laila

    August 5, 2026

    How Motherhood Is Redefining Leadership for Women Founders

    August 4, 2026
    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    Copyright © 2025 Populist Bulletin. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.