Breaking 16:47 Bank Cards in Syria: Payment Giants Restart International Transactions 16:42 Wheat Prices Surge Amid Black Sea Tensions and Climate Risks 16:35 Mercosur-Singapore: Argentina Approves Trade Agreement with Asia 16:19 Ebola in the DRC: UN warns of faster spread than response capabilities 16:06 Agadir Enhances Its Security Measures with a New Regional Explosives Unit 15:58 Julián Álvarez: Atlético Madrid says no to Barça and rejects all negotiations 15:57 Floods in Nepal and Tibet: Death toll exceeds 350, over 1,300 missing 15:40 A World First: Brain Tumor Removed with the Help of Artificial Intelligence 15:09 Tunisia: Kais Saied denounces 'premeditated' acts behind water and electricity cuts 14:57 Ceuta: Madrid dismisses any evidence of Morocco's involvement in the migrant influx 14:49 Culture and Environment: Highlights from the 22nd Edition of the Beach Festival 14:37 European Union: Meta urged to enhance protection for teenagers on Instagram and Facebook 14:34 Iran: Moscow Rejects US Sanctions, Islamabad Clarifies Its Position 14:33 FIFA: Saudi Arabia Backs Gianni Infantino Amid Governance Criticism 14:14 Ouzoud Hosts the 4th Edition of the International Mountain Film Festival 14:12 Germany: Nearly 15,800 Heat-Related Deaths Since April 2026 14:08 Quebec Moroccan Festival: 5th Edition Celebrates Cultural Dialogue 14:00 US Inflation and Fed Rates: Dollar Strengthens Ahead of Jackson Hole 13:55 Artificial Intelligence: Morocco Leads North Africa in Governance 13:45 EU Budget 2028-2034: Six Countries Demand Cuts of Several Hundred Billion Euros 13:40 Russia-NATO: Moscow Denies Any Threat After CIA Director's Secret Visit 13:31 Italy: Government Extends Tax Relief on Diesel Until September 5 13:26 Global Reputation: Morocco Ranks 27th in RepCore Nations 2026 13:21 Early Diet May Influence Cancer Risk Decades Later 13:06 Dakhla: the marketing of clams and Boutalha oysters is once again authorized 13:06 Chinese Robotics: Material Dominance Hindered by Lack of AI 13:02 His Majesty the King congratulates the President of the Republic of Moldova on her country's national holiday 11:30 Spain: Wildfires Slow Down After a Week Marked by Nearly 1,000 Hectares Burned 11:23 Ceuta: twelve Moroccans arrested following attack on Spanish military vehicle 11:20 Maghrebail Strengthens Its Performance in the First Half of 2026 11:20 Cartier Saada: Revenue Declines by 28.5% in Q1 2026-2027 11:13 Morocco–UK: London Explores a New Agreement on Public Procurement 11:11 Nepal: 33 Britons Missing After Deadly Flood 11:06 Towards 2030: How Rabat is Reinventing Its Hotel and Tourism Model 11:05 South Korea: A Roadmap to Accelerate the Ecological Transition of Maritime Transport 10:59 Lamhiriz: Fishing Landings Surge by 54% by the End of July 2026 10:59 Humanoid Robots: Hyundai Prepares for Their Commercialization in Its Dealership Network 10:56 Souss-Massa: A 15 Billion Dirham Desalination Project to Strengthen Water Security 10:54 Armenia: Former President Robert Kotcharian Detained in Corruption Case 10:41 Nepal: Death toll from devastating floods reaches 270 with over 800 missing 10:38 Spain: The Villena Treasure Stolen in a Lightning-Fast Burglary 10:35 War in Ukraine: Moscow Warns France and the UK After Their Military Support for Kiev 10:31 Ceuta: tensions rise between residents and migrants after new clashes 10:22 South Korea: Bank of Korea Raises Growth Forecast to 3.3% for 2026 10:05 Australia Excludes AI-Generated Music from Its Charts 09:51 South Korea: Artificial Intelligence Emerges as a Major Productivity Lever 09:33 Gas Stations in Morocco: Towards Mandatory Integration of Renewable Energies 09:06 Google launches Gemini 3.5 Transcribe to enhance real-time voice transcription 09:00 Abderrahim Fakir Case: Initial Cardiac Exams Rule Out Pre-existing Conditions 08:56 Earthquake in Colombia: Beyoncé Donates One Million Dollars to Aid Victims 08:50 Iran and Russia: Pezeshkian Expected in Kyrgyzstan for New Meeting with Putin 08:43 Pancreatic Cancer: FDA Approves New Treatment That Extends Patient Survival 08:37 Hormuz Strait: A Ship Hit by a Projectile, Fire Contained Onboard 08:30 Colombia: a 5.1 magnitude earthquake shakes Bogotá and several cities 08:25 Nvidia and Hugging Face: a $12.9 billion acquisition that could disrupt open source AI 08:14 United States: Donald Trump Declares State of Emergency to Protect the Electric Grid 08:02 CIA in Moscow: A Discreet Visit Amid Rising Tensions Between Russia and NATO 07:51 Dengue in Bangladesh: 88 deaths and over 31,000 cases reported this year 07:43 Phosphate Fertilizers: Moroccan Giant OCP Builds Its First U.S. Plant in 40 Years 07:36 Nepal and Tibet: Deadly Disaster Leaves Over 1,000 Missing 07:30 Syria: The United States Removes Damascus from Its List of Terrorism-Supporting Countries 07:28 Press Review in Morocco: Gaming, High-Speed Rail, Mobility, and Major Projects in the Spotlight

Lovable denies breach after api flaw exposed user project data

Tuesday 21 April 2026 - 16:20
By: Dakir Madiha
Lovable denies breach after api flaw exposed user project data

Lovable is facing scrutiny after a security researcher revealed that a simple API vulnerability allowed unauthorized access to sensitive data across thousands of user projects. The company has denied that a data breach occurred, even as details of the flaw raised concerns about access controls and platform security.

The vulnerability, disclosed by a researcher known as @weezerOSINT, affected projects created before November 2025. It was identified as a broken object level authorization flaw, in which the system failed to verify whether a user had permission to access specific resources. According to the researcher, only five API calls from a free account were required to retrieve complete project data belonging to other users, including source code, database credentials, AI conversation histories, and customer information.

The issue was initially reported on March 3 through HackerOne, but the report was classified as a duplicate and closed without escalation to Lovable’s internal security team. Reviewers reportedly considered the behavior consistent with existing platform design, where some project elements had historically been accessible. The vulnerability remained unaddressed for 48 days before being publicly disclosed.

Lovable’s response evolved over the course of Monday. The company first stated that no data breach had occurred and attributed the exposure to unclear documentation around what constituted a “public” project. It later acknowledged that a backend change introduced in February had unintentionally restored access to project conversation histories, a feature that had previously been restricted. The company said it reversed the change immediately after becoming aware of the issue.

The startup, which reports a valuation of 6.6 billion dollars and lists companies such as Uber and Zendesk among its users, maintained that it had not been notified earlier because the bug report was not forwarded. It added that public project conversations are no longer accessible and that steps have been taken to prevent similar exposures.

The incident follows a pattern of security concerns linked to AI generated applications on the platform. Earlier in 2026, researcher Taimur Khan found that a significant number of featured apps contained critical vulnerabilities, including one case that exposed data from more than 18,000 users. The root cause was traced to missing row level security policies in databases, a recurring weakness in AI generated code that functions correctly but lacks proper access controls.

The latest disclosure has intensified debate حول the security of so called “vibe coding” platforms, which allow users to build applications through natural language prompts. Experts warn that while such tools accelerate development, they can also introduce systemic risks if generated code is not rigorously audited. The Lovable case highlights how design assumptions and overlooked authorization checks can expose large volumes of sensitive data at scale.


  • Fajr
  • Sunrise
  • Dhuhr
  • Asr
  • Maghrib
  • Isha

Read more

This website, walaw.press, uses cookies to provide you with a good browsing experience and to continuously improve our services. By continuing to browse this site, you agree to the use of these cookies.