Observed Signal · Jul 12, 2026 · Security Audit · Source: DEV Community · Impact: 2/5 · Sentiment: Negative

Scan: 15 Lovable Apps — 40% Expose DB in Browser

Executive Signal Summary

A developer scanned 15 public apps built on the Lovable ecosystem and found widespread client-side exposure of databases and missing basic web hardening. The scan found 6 of 15 apps load Supabase directly in the browser (including a public API key in page source) and 14 of 15 apps shipped no Content-Security-Policy. Two real-world audits (performed with owners' permission) revealed readable user profile data including password hashes and a paid learning app whose entire paid catalogue was accessible without authentication. The author notes the core mistake is not exposing Supabase client-side but failing to enforce Row-Level Security (RLS) at the database layer, and published a free passive surface-check tool at sealdy.dev.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Reveals common, easily remediable misconfigurations that can expose user data and paid content; important for web developers and SaaS operators but limited scope outside developers using these platforms.

SIGNAL RADAR

Track Lovable Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • 6 of 15 scanned public Lovable apps load their Supabase database directly client-side, exposing a public API key in page source.
  • 14 of 15 scanned apps did not set a Content-Security-Policy.
  • Two audited apps (with owner permission) exposed sensitive data: one exposed profile data including a password hash; another exposed 155 paid study sheets and 4,872 answers to unauthenticated users.
  • The author states the root cause is missing database-level access controls (Row-Level Security) rather than using Supabase client-side.
  • The author published a free passive surface-check tool available at sealdy.dev.

Connected Companies & Entities

10 Entities mapped

“6 of 15 load their Supabase database directly client-side. The public API key sits in the page source....”

“If you built something on Lovable / Bolt / Replit with real users (or paying ones), it's worth 60 seconds to check what a stranger can alrea...”

“If you built something on Lovable / Bolt / Replit with real users (or paying ones), it's worth 60 seconds to check what a stranger can alrea...”

“If you built something on Lovable / Bolt / Replit with real users (or paying ones), it's worth 60 seconds to check what a stranger can alrea...”

“DEV Community — A space to discuss and keep up software development and manage your software career...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 12, 2026
Original Coverage Title: “I scanned 15 public Lovable apps. 40% load their database in the browser.”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecuritySep 25, 2026

Supabase data exposure: 16,000 databases leaking personal data

Cybersecurity firm UpGuard has discovered that approximately 16,000 databases hosted by Supabase, a popular development platform for AI vibe-coded apps, are exposing sensitive personal data to the public web. The exposed data includes names, addresses, phone numbers, and passwords, some of which are linked to sensitive projects like an Indian adult streaming site, a U.S. valet service, an immigration service, and even an African consulate. While Supabase, which recently reached a $10 billion valuation, has made security improvements, its CISO Bil Harmer emphasized that security is a shared responsibility and that projects are 'secure by default'. The findings highlight the growing risk of data breaches due to misconfigured AI-generated applications, as the ease of building apps with AI tools often leads to security flaws.

Read assessment
Developer Tools & Data PrivacyAug 25, 2026

Dev tools you paste data into can cause breaches

The article warns that third-party developer tools (online JSON formatters, regex testers, Base64 decoders, etc.) can be a major source of data exposure because users often paste sensitive data (API keys, auth tokens, production payloads) into them without verifying whether the site logs or ships that data. It cites a reported incident where a threat actor is selling roughly 3.6 million employee records taken from Microsoft Azure environments across multiple Fortune 500 companies. The author presents FormatStack, a set of browser-only developer utilities that perform all processing client-side so pasted content never leaves the user’s machine.

Read assessment
Large Language Models (LLM) & AIApr 15, 2026

Claude Mythos Exposes Mobile App Security Risks

Anthropic’s Claude Mythos model autonomously discovered thousands of critical software vulnerabilities — including a 27-year-old bug in OpenBSD’s TCP SACK implementation — prompting Anthropic to restrict access to a consortium called Project Glasswing so major vendors can patch findings before wider release. The article warns that the same AI capability will be applied to compiled mobile binaries, increasing risk for iOS and Android apps which ship as readable binaries, contain high-value secrets, and are slow to patch. It outlines mobile application security best practices — continuous mobile app security testing (MAST), code hardening/obfuscation, runtime application self-protection (RASP), app attestation, and threat monitoring — and highlights Guardsquare products (AppSweep, iXGuard) and ProGuard heritage as relevant defenses.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.