The promise of “vibe coding” is simple, describe the app you want, let AI generate the code, and ship. But a recent security probe shows the reality can be a lot messier.
Lovable, an AI app-building platform that generates full applications from prompts, is facing criticism after a security researcher discovered major vulnerabilities in one of the apps hosted on its platform. The app featured on Lovable’s Discover page and viewed more than 100,000 times exposed the data of more than 18,000 users.

The researcher, tech entrepreneur Taimur Khan, said he found 16 vulnerabilities in the project, including six critical flaws. The app itself wasn’t publicly named during disclosure, but it was reportedly an education platform used by teachers and students to generate exams and review grades. Some users appeared to come from major universities and K-12 institutions, raising the stakes given the potential exposure of student information.Read more