Fetching from the wire…
Top 5 · 2026-04-21 · source-backed
Security researcher @weezerOSINT demonstrated that any free Lovable account could access other users' source code, database credentials, AI chat histories, and customer data via a Broken Object Level Authorization (BOLA) flaw. Every project created before November 2025 was exposed. Tens of thousands of developers affected.
Researchers pulled hardcoded Supabase credentials revealing real names and Stripe customer IDs from organizations including Accenture Denmark. This isn't theoretical. This is real customer financial data accessible to anyone with a free account.
Lovable's response made things worse. They initially denied the breach, then described the exposed credentials as "intentional behavior." The security community's reaction was predictable and justified. A 4chan greentext retelling of the saga got 2,200 likes. A separate tweet claiming to show vibe coding erasing "$31B company" infrastructure in 184 seconds hit 1.35 million views.
I've been saying for months that vibe coding's speed-to-ship advantage has a hidden cost, and this is what it looks like. When you generate a full-stack app in minutes, who audits the auth layer? Who checks if your API endpoints enforce object-level authorization? Who verifies that database credentials aren't hardcoded in client-accessible locations?
The BOLA flaw is entry-level security. It's literally item one on the OWASP API Security Top 10. This isn't a sophisticated attack vector. It's the absence of basic access control on API endpoints. And it persisted for months across a platform valued at $5 billion.
The broader pattern is clear. Vibe-coded infrastructure ships fast and breaks in predictable ways. The vulnerabilities aren't exotic. They're the same ones we've been teaching junior developers to avoid for a decade. The difference is that vibe coding generates these vulnerabilities at scale, across thousands of projects simultaneously, with no code review step in the loop.
For builders who've used Lovable or similar vibe coding platforms: audit your infrastructure this week. Check for hardcoded credentials. Verify object-level authorization on every API endpoint. Test whether authenticated users can access other users' resources by manipulating IDs. If you built something with a vibe coding tool before November 2025 and haven't audited it, assume it's vulnerable until proven otherwise.
Each link below shares sources, entities, or timing with this story.
Israeli cybersecurity startup RedAccess found 380,000 apps built with Lovable, Replit, Base44, and Netlify publicly accessible with virtually no security. About 5,000 of those are actively leaking medical records, financial data, customer chatbot logs, and corporate secrets. D...
Salesforce unveiled Headless 360 at TDX, and this is the most aggressive enterprise platform pivot I've seen. Every capability across Customer 360, Slack, Agentforce, and Data 360 is now accessible via APIs, MCP tools, or CLI commands. No browser. No clicking through the Sales...
I've been saying for months that the missing piece in agentic coding isn't smarter models. It's that agents can't provision anything. They can write code all day but the moment they need a database, an auth provider, or a hosting account, a human has to step in, click through...
Armature ran 16,893 coding sessions, 5,292 of which were valid, across 75 repositories, 10 languages, 1,163 prompt variations and 4 user personas, rotating E2B, Blaxel and Daytona sandboxes to kill provider bias. Nobody has published a controlled study at this scale before. Ar...
The man who coined "vibe coding" a year ago now declares it passe and introduces "agentic engineering" — the discipline of orchestrating AI agents that plan, write, test, and ship code under structured human oversight. The timing isn't accidental. Escape.tech released the larg...
YC's latest batch is roughly 95% AI-generated code. Founders are shipping SaaS MVPs in days, with Cursor and Claude Code cutting build time 3 to 5x and free tiers on Supabase, Vercel, and Resend widening the runway, per Superframeworks. The speed story is over. It won. Vibe co...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.