On April 20, a security researcher who goes by the handle @weezerOSINT on X claimed the vibe-coding platform Lovable AI suffered a data breach that allowed the source code, credentials, chat history, and even customer data from projects to be accessed by other users.
Lovable responded on X by denying that a breach had occurred, saying, "We were made aware of concerns regarding the visibility of chat messages and code on Lovable projects with public visibility settings. To be clear: We did not suffer a data breach.”
Now, three days after its initial statement, the company appears to be walking back that position in a recent blog post released yesterday, saying that it fixed the issue within two hours of the report on April 20.
“On April 20, a security researcher publicly reported that data within public Lovable projects could be accessed by any authenticated user. We shipped a fix within two hours, but both our product and initial external response missed the mark. We owe you a clearer accounting of what happened, why it happened, and what we’re doing about it,” it said.
Subscribe for free to continue reading this article
Subscribe SubscribeAlready Have an Account? Log In