ADVERTISEMENT

Lovable goes on ego trip denying vulnerability, then blames others for said vulnerability

Vibecoding platform Lovable has admitted a serious flaw in its service after, bizarrely, first denying the vulnerability and blaming the alleged misunderstanding on unclear documentation and design. Then it threw HackerOne, the bug-bounty service, under the bus.

lovable-scandal

Image by Cybernews.

Gintaras Radauskas
Gintaras Radauskas Senior Journalist
April 21, 2026 Updated: April 21, 2026 4 min read

No hacking needed to trigger the bug

jurgita color justinas color Izabele Pukenaite vilius color ernestas color gintaras color
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google
Add us as your Preferred Source on Google.

Prompts and source code are visible intentionally

ADVERTISEMENT

An apology and some finger-pointing

The company apparently did nothing because HackerOne believed that seeing public projects’ chats was the intended behavior, although it’s hard to be surprised, since that’s exactly how Lovable has marketed its product historically.

ADVERTISEMENT