Evidence · DiggingBeagle record
Methodology: How we discovered over 2k high-impact vulnerabilities in apps built with vibe coding platforms
Escape describes a one-time scan of more than 5,600 public applications built with several vibe-coding platforms, reporting more than 2,000 vulnerabilities, more than 400 exposed secrets and 175 PII exposures while documenting sampling, temporal and platform-imbalance limitations.
- Published
- Oct 29, 2025
- Source role
- primary disclosure
Evidence record
Escape describes a one-time scan of more than 5,600 public applications built with several vibe-coding platforms, reporting more than 2,000 vulnerabilities, more than 400 exposed secrets and 175 PII exposures while documenting sampling, temporal and platform-imbalance limitations.
Claim-level citations (1)
- supportsA scan of 1,645 Lovable projects found 170 with inadequate database RLS: A later Escape study of more than 5,600 publicly available vibe-coded applications across several platforms reported more than 2,000 vulnerabilities, 400+ exposed secrets and 175 instances of exposed PII. Lovable accounted for roughly 4,000+ applications in Escape's initial platform coverage, but Escape explicitly warns that its one-time dataset has sampling, temporal and platform-imbalance bias. The study therefore corroborates the broader class of exposed backend and authorization failures without providing a directly comparable Lovable-specific prevalence estimate.
Methodology sections 'Data Gathering Strategy' and 'Observations and Biases': more than 5,600 public applications analyzed; initial platform coverage included Lovable at roughly 4,000+ applications; more than 2,000 vulnerabilities, 400+ exposed secrets and 175 PII exposures reported; sampling, temporal and platform-imbalance limitations are explicitly stated.