PT-2025-23236 · Lovable · Lovable
Kody Low
+1
·
Published
2025-05-30
·
Updated
2026-04-20
·
CVE-2025-48757
CVSS v3.1
9.3
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lovable versions through 2025-04-15
Description
An insufficient database Row-Level Security (RLS) policy in Lovable allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. This issue stems from insecure defaults and a lack of RLS validation before deployment. Reports indicate that over 300 insecure endpoints were exposed, potentially impacting over 170 applications. The vulnerability allowed unauthenticated users to manipulate entire database tables in production environments.
Recommendations
For versions through 2025-04-15, ensure robust Row-Level Security policies are implemented and thoroughly validated before deploying applications.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lovable