PT-2025-23236 · Lovable · Lovable

Kody Low

+1

·

Published

2025-05-30

·

Updated

2026-04-20

·

CVE-2025-48757

CVSS v3.1

9.3

Critical

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lovable versions through 2025-04-15
Description An insufficient database Row-Level Security (RLS) policy in Lovable allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. This issue stems from insecure defaults and a lack of RLS validation before deployment. Reports indicate that over 300 insecure endpoints were exposed, potentially impacting over 170 applications. The vulnerability allowed unauthenticated users to manipulate entire database tables in production environments.
Recommendations For versions through 2025-04-15, ensure robust Row-Level Security policies are implemented and thoroughly validated before deploying applications.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-48757

Affected Products

Lovable