Evidence · DiggingBeagle record
Statement on CVE-2025-48757
Matt Palmer's primary disclosure reports inadequate Supabase Row Level Security across Lovable-generated projects, including 303 exposed endpoints across 170 of 1,645 analyzed projects and a later unauthorized write test against Linkable.
- Published
- May 29, 2025
- Source role
- primary disclosure
Evidence record
Matt Palmer's primary disclosure reports inadequate Supabase Row Level Security across Lovable-generated projects, including 303 exposed endpoints across 170 of 1,645 analyzed projects and a later unauthorized write test against Linkable.
Claim-level citations (3)
- supportsA scan of 1,645 Lovable projects found 170 with inadequate database RLS: Palmer reports that a March 21, 2025 scan identified 303 endpoints across 170 of 1,645 analyzed Lovable projects with inadequate Row Level Security settings.
Automated Scan Findings, reporting 303 endpoints across 170 projects, approximately 10.3% of 1,645 analyzed
- supportsA scan of 1,645 Lovable projects found 170 with inadequate database RLS: In a May 2025 Linkable follow-up, Palmer reports that an unauthenticated request could insert a record with payment_status set to paid, demonstrating an integrity impact in addition to read exposure.
Data Modification Vulnerability section and Appendix A2
- contextA scan of 1,645 Lovable projects found 170 with inadequate database RLS: The public CVE record describes insufficient RLS allowing unauthenticated reads or writes but records the issue as disputed because Lovable says customers are responsible for protecting their application data.
Disclosure statement attributing recurring insecure RLS configurations to Lovable-generated projects