Is my Lovable app secure?
Lovable gets an app running quickly, with a Supabase database and sign-in wired in. The rules that decide who can read which row are part of your app, and they are the part to check before real users arrive.
What Lovable handles.
- ✓Hosting for the published app, served over HTTPS
- ✓A Supabase database and sign-in, wired in for you
- ✓A Secrets store, and a prompt to move keys there when you paste one into the chat
- ✓A quick security scan at publish that reviews database access rules and dependencies, and a deeper scan on request
From the platform’s own documentation: Lovable docs: Security
What stays yours.
- →Row level security on every table, and the policy behind each one
- →Storage bucket settings, and which files anyone with a link can open
- →Keys for paid services kept in Secrets and called from server code, never from the browser
- →Project visibility, and what a public project shows to other people
- →Security headers on the published app
Documented.
Public reports that involve Lovable or apps built on it, dated and linked. Each line says what its source says, and nothing more.
- May 29, 2025CVE-2025-48757: Supabase tables readable with the public key
Matt Palmer found 303 endpoints across 170 Lovable-built projects where the public anon key in the browser allowed direct queries to Supabase tables that lacked row level security. He reported it privately on 2025-03-21 and published on 2025-05-29.
Source: Superblocks, March 9, 2026 - April 27, 2026Chat histories of public projects readable by other users
Halborn reports that a February 2026 update to Lovable’s permission backend re-enabled access to the chats of public projects on the entry tier. Per Halborn, the patch first covered new projects, and older public projects stayed exposed until after public disclosure in April 2026.
Source: Halborn, April 27, 2026 - June 2, 2026A scan of 1,072 Supabase-backed apps
Symbiotic Security scanned 1,072 apps built with Lovable, v0, Bolt.new, Replit and Windsurf that use Supabase. It reports that 98% had at least one vulnerability, 308 exposed the anon key in JavaScript, 172 allowed data to be changed or deleted without signing in, and 197 had a CORS misconfiguration on the Supabase API.
Source: Symbiotic Security, June 2, 2026 - May 7, 2026About 380,000 public assets built with AI coding tools
eWeek reports that Red Access found about 380,000 publicly accessible assets created with AI coding tools, on platforms including Lovable, Replit, Netlify and Base44, and that around 5,000 of them exposed potentially sensitive information such as medical and financial records.
Source: eWeek, May 7, 2026
A five minute check.
In your own Lovable dashboard, in this order.
- Run the security scanOpen the project’s Security view and run the scan. Read the database findings first; they are the ones that expose data.
- Confirm row level security on every tableIn the database view (or your Supabase dashboard, if you connected your own project), every table in the public schema should show RLS enabled.
- Read each policyA policy whose condition is simply true lets everyone through. Tables that hold one person’s data should compare auth.uid() to an owner column.
- Check project visibilityIn the project settings, confirm whether the project is public. A public project can show its code and chat history to other people.
- Search the published app for keysOpen the live app, open the browser’s developer tools, and search the loaded scripts for service_role, sk_live and secret. Only the public anon or publishable key belongs there.
Questions.
Is the Supabase anon key in my Lovable app a leak?
No. Supabase documents the publishable key as safe to expose, on the condition that row level security is on. The key becomes a problem only when a table it can reach has no RLS or an open policy.
Lovable’s scan came back clean. Am I done?
It is a good sign. The scan reads your access rules; it cannot know which data your business considers private, or whether a policy matches how your customers should see each other. That judgement is the audit.
Do I have to leave Lovable to fix this?
No. Policies, storage settings and secrets are fixed inside the same Supabase project. Most apps keep building in Lovable after.
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
How it works, in four steps.
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →