Back to feed
Dev.to
Dev.to
7/12/2026
I scanned 15 public Lovable apps. 40% load their database in the browser.

I scanned 15 public Lovable apps. 40% load their database in the browser.

Short summary

A passive scan of 15 public Lovable-built apps found 40% expose their Supabase database client-side, with 14 of 15 lacking Content-Security-Policy. Two audited apps leaked user data and entire paid catalogues because RLS was misconfigured and paywalls existed only in the front-end. The author released a free passive scanning tool at sealdy.dev for builders to check their exposure.

  • 6 of 15 Lovable apps load Supabase client-side with public API keys, vulnerable if RLS is misconfigured
  • 14 of 15 apps ship no Content-Security-Policy header
  • Real-world leaks found: password hashes and 155 paid study sheets readable by unauthenticated users

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more