Missing Row Level Security, and a disputed CVE
CVE-2025-48757, filed after security researcher Matt Palmer’s findings in March 2025, describes insufficient Row Level Security in Lovable-generated sites, allowing unauthorized reads and writes; a follow-up scan found 170 of 1,645 tested apps exposed across 303 endpoints (Superblocks, 2025). Honesty requires the other half: the CVE is formally disputed by the vendor, NVD assigns it no score of its own, and the 8.26 severity figure comes from third parties. Lovable now applies RLS to newly generated schemas; apps generated earlier stay vulnerable until someone fixes them by hand (VibeAppScanner status review, 2026).