{"id":11241,"date":"2026-04-21T18:00:31","date_gmt":"2026-04-21T18:00:31","guid":{"rendered":"https:\/\/wildgreenquest.com\/?p=11241"},"modified":"2026-04-21T18:00:31","modified_gmt":"2026-04-21T18:00:31","slug":"lovable-left-ai-prompts-and-user-data-exposed-one-researcher-found","status":"publish","type":"post","link":"https:\/\/wildgreenquest.com\/?p=11241","title":{"rendered":"Lovable left AI prompts and user data exposed, one researcher found"},"content":{"rendered":"<p><br \/>\n<br \/><\/p>\n<p>A researcher revealed that the vibe-coding platform Lovable exposed users\u2019 chat histories with AI models to other users accessing the platform through an API (application programming interface).<\/p>\n<p>X user <a rel=\"nofollow\" href=\"https:\/\/x.com\/weezerOSINT\">@weezerOSINT<\/a>, reported the exposure in a <a rel=\"nofollow\" href=\"https:\/\/x.com\/weezerOSINT\/status\/2046170666131669027\">post on Monday<\/a>. \u201cI made a Lovable account today and was able to access another user&#8217;s source code, database credentials, AI chat histories, and customer data are all readable by any free account,\u201d the researcher wrote. The post included a screenshot of another Lovable user\u2019s project code and chats, along with an unresolved ticket for the bug that allegedly caused the data leak.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Lovable has a mass data breach affecting every project created before november 2025.<br \/>I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. <br \/>nvidia,\u2026 <a rel=\"nofollow\" href=\"https:\/\/t.co\/QcVvz9cNZl\">pic.twitter.com\/QcVvz9cNZl<\/a><\/p>\n<p>&mdash; impulsive (@weezerOSINT) <a rel=\"nofollow\" href=\"https:\/\/twitter.com\/weezerOSINT\/status\/2046170666131669027?ref_src=twsrc%5Etfw\">April 20, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>In a follow-up conversation with <em>Fast Company<\/em>, @weezerOSINT (who did not share his real name) says it took 30 minutes using xAI\u2019s Grok 4.2 model to conduct the research, adding that before AI, finding similar exposures would take hours or days.<\/p>\n<p>@weezerOSINT reported the issue via HackerOne, a cybersecurity company that runs bug bounty and vulnerability disclosure programs, in early March. On Monday, the researcher showed that Lovable projects created before November 2025 still expose the data.<\/p>\n<p>Lovable declined to provide an executive to explain the situation, and pointed to its public statement on X.<\/p>\n<p>Lovable <a rel=\"nofollow\" href=\"https:\/\/x.com\/Lovable\/status\/2046270357674299623\">initially said on X<\/a> that no \u201cdata breach\u201d had occurred, and that exposing project code was \u201cintentional behavior.\u201d When users mark their projects \u201cpublic,\u201d the company explained, they opt to have their code visible to other users.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings.<br \/>To be clear: We did not suffer a data breach.<br \/>Our documentation of what \u201cpublic\u201d implies was unclear, and that\u2019s a failure on us.<br \/>Specifically\u2026<\/p>\n<p>&mdash; Lovable (@Lovable) <a rel=\"nofollow\" href=\"https:\/\/twitter.com\/Lovable\/status\/2046270357674299623?ref_src=twsrc%5Etfw\">April 20, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>But that did not account for the exposure of users\u2019 chats and prompts with the AI model, which Lovable made accessible for public projects until recently.<\/p>\n<p>\u201cWe also retroactively patched our API so public project chats couldn&#8217;t be accessed, no matter what,\u201d Lovable said in a second, <a rel=\"nofollow\" href=\"https:\/\/x.com\/Lovable\/status\/2046301006795870346\">clarifying post<\/a> on X. \u201cUnfortunately, in February, while unifying permissions in our backend, we accidentally re-enabled access to chats on public projects.&#8221;<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">We\u2019re sorry our initial statement didn&#039;t properly address our mistake. Here&#039;s what a public project on Lovable means, and how we got to where we are today:<br \/>In the early days, people didn&#039;t know what Lovable was capable of. So we wanted to make it easy to explore what others were\u2026 <a rel=\"nofollow\" href=\"https:\/\/t.co\/8X2LMjETaS\">https:\/\/t.co\/8X2LMjETaS<\/a><\/p>\n<p>&mdash; Lovable (@Lovable) <a rel=\"nofollow\" href=\"https:\/\/twitter.com\/Lovable\/status\/2046301006795870346?ref_src=twsrc%5Etfw\">April 20, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>As for @weezerOSINT\u2019s early-March report to HackerOne, Lovable says the ticket had been closed because its \u201cHackerOne partners\u201d believed that viewing public projects\u2019 chats was \u201cthe intended behavior.\u201d<\/p>\n<p>As a vibe-coding platform, Lovable treats natural-language prompts used to generate code as a core part of the building process. The company initially believed its community would benefit from seeing how other developers used prompts to build features, functions, components, or database schemas, so chats were treated as standard project metadata.<\/p>\n<p>But the risk of exposing sensitive information in those chat histories appears to have outweighed that benefit. Lovable says that in December 2025 it made all new projects \u201cprivate by default\u201d for all users.<\/p>\n<p>Lovable\u2019s <a rel=\"nofollow\" href=\"https:\/\/www.nytimes.com\/2025\/12\/18\/business\/dealbook\/lovable-a-start-up-that-makes-anyone-a-coder-raises-330-million.html\">most recent funding round<\/a> came in December 2025, when it raised $330 million from CapitalG, Menlo Ventures, Khosla Ventures, and others. After the round, the company was valued at $6.6 billion, reportedly tripling its valuation in about five months.<\/p>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/www.fastcompany.com\/91530092\/lovable-left-ai-prompts-and-user-data-exposed-researcher-found\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A researcher revealed that the vibe-coding platform Lovable exposed users\u2019 chat histories with AI models to other users accessing the platform through an API (application programming interface). X user @weezerOSINT, reported the exposure in a post on Monday. \u201cI made a Lovable account today and was able to access another user&#8217;s source code, database credentials,<\/p>\n","protected":false},"author":1,"featured_media":11242,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[],"class_list":{"0":"post-11241","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-brand-spotlights"},"_links":{"self":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/11241","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11241"}],"version-history":[{"count":0,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/11241\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/media\/11242"}],"wp:attachment":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11241"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11241"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11241"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}