Vibe coding upstart Lovable denies data leak, cites 'intentional behavior,' then throws HackerOne under the bus
Vibe coding platform Lovable has denied a data leak, citing 'intentional behavior' and blaming bug-bounty service HackerOne, despite a researcher finding that anyone could access sensitive user info. The leak stems from a Broken Object Level Authorization vulnerability, which Lovable claims is by design for public projects. The company's response has been criticized as an example of an AI firm shirking responsibility for security flaws.