back to article Lovable-hosted app littered with basic flaws exposed 18K users, researcher claims

Vibe-coding platform Lovable has been accused of hosting apps riddled with vulnerabilities after saying users are responsible for addressing security issues flagged before publishing. Taimur Khan, a tech entrepreneur with a background in software engineering, found 16 vulnerabilities – six of which he said were critical – in a …

  1. IGotOut Silver badge
    WTF?

    OK two things have pissed me off with this article.

    1. Lovable knew there were security issues, but were "Meh fuck the end user"

    2. The security researcher didn't name the app. WTF? You've blatantly stated that this app is leaking thousands of peoples personal data and they are like "Meh, fuck the end user"

    1. Anonymous Coward
      Anonymous Coward

      Re: OK two things have pissed me off with this article.

      I sort of get your point BUT ...

      By NOT naming the 'Vi-coded' app then maybe all the apps of the same class will be treated with appropriate and extreme wariness !!!

      This wider aim is a possible counter to the original lack of attribution and subsequent 'naming & shaming' !!!

      :)

    2. Anonymous Coward
      Anonymous Coward

      Re: OK two things have pissed me off with this article.

      > 2. The security researcher didn't name the app. WTF? You've blatantly stated that this app is leaking thousands of peoples personal data and they are like "Meh, fuck the end user"

      The app is pissing personal details everywhere and the owners are too dumb/apathetic to fix it. Since it's NOT fixed, there's no real incentive to advertise exactly where to collect all this information.

    3. Oli.

      Re: OK two things have pissed me off with this article.

      The core issue is with the platform, not with the app. Even if the platform wants to offload it to the "developer" (read: "vibe coder" (read: contributor to humanity's downfall)).

      Well, the core core issue is with GenAI corporations who keep on overselling their products to prevent the bubble from bursting. Call me accelerationist, but I hope we'll soon see some big service fail catastrophically because of AI contribution to its code.

  2. Anonymous Coward
    Anonymous Coward

    Waiting for the vibe-debug AI

    And the vibe-security-check AI

    There could be a whole toolchain of AIs !

  3. desht
    Mushroom

    VIBE

    Vastly insecure, but executes.

  4. billdehaan

    I'll take door number three, Alex

    Who's to blame – the vibey platforms or the humans who ignore security warnings?

    As the saying goes, "embrace the healing power of and".

  5. Greybearded old scrote

    A bad workman blames his tools

    But then, a good workman buys from Snap-on not Wilko.

  6. Anonymous Coward
    Anonymous Coward

    16 vulnerabilities, 6 critical, 18K users exposed from a single vibe-coded app

    The post-mortem will blame Lovable. The real failure was treating security scanning as a post-publish option instead of a pre-ship requirement. Optional audits don't stop breaches. Embedded controls do.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon