Company · Argument

Security of generated applications

Read 3 days ago · 3 readings on record

0
declares

as its own pages describe it; none was tested

6
users raised

themes in public — opinions, not a measurement

11
claims on record

each with its date, tag and source

1
sectors

placed in, on the map

What each week held

Read in 3 of the last 12 weeks. The other 9 were not read at all, and are drawn empty rather than as quiet.

The bar is observed claims in that week. A dashed marker is a week this company was not read at all — not a quiet one. Inferences and failed reads are in neither.

What it declares

The reading listed none. That is what the reading listed, not a statement that this product carries nothing.

What users raised

  • hardcoded/client-exposed API keys
  • missing Row Level Security on Supabase tables
  • service_role key exposed to client bypassing RLS
  • VITE_/NEXT_PUBLIC_ env vars shipping secrets to browser
  • no auth checks on data endpoints
  • secrets leaked via AI chat/debugging history

Themes people raised in public. A complaint is somebody’s opinion, not a measurement of the product.

Everything on record

11 observed claims. Newest first; the tag on each row is what kind of claim you are reading.

  • COMPLAINTFACTSep 28, 2026

    A Hacker News-linked scan (SupaExplorer) found 11% of vibe-coded apps leak Supabase keys, and a separate scan by Symbioticsec of 1,072 vibe-coded apps found 98% had security flaws, with 39 sites having tables fully readable via the exposed anon key.

    Reinforces the complaint theme's independent sighting count with additional, larger-scale quantified evidence, though these specific scans predate the last ledger entry and are cited here mainly as corroborating context rather than new material.

    www.symbioticsec.ai/blog/we-scanned-1-072-vibe-coded-apps-98-had-security-flaws
  • PRODUCTCOMPANY CLAIMSep 28, 2026

    Supabase's CISO Bil Harmer responded to the new research by stating the company's projects are "secure by default" and that it provides secure defaults and tooling while customers control their own project configuration.

    First on-record vendor pushback captured in this cycle, positioning Supabase's stance as responsibility-shifting to developers/AI tools rather than the platform itself, consistent with Lovable's earlier CVE dispute.

    cybernews.com/news/16000-supabase-databases-exposed/
  • PRODUCTFACTSep 28, 2026

    A separate, newly disclosed flaw in Lovable exposed users' source code, database credentials, AI chat histories, and customer data, on top of the previously known RLS/hardcoded-secret issues.

    Adds a new vulnerability class (source code/chat-history/credential exposure) to Lovable's track record beyond the earlier CVE-2025-48757 RLS issue, deepening the pattern of platform-level security gaps.

    cybernews.com/news/16000-supabase-databases-exposed/
  • DISCOURSEFACTSep 28, 2026

    Cybernews, citing researcher scans and TechCrunch reporting, found that roughly 16,000 Supabase databases tied to vibe-coded apps are exposed, with additional leak vectors including inadequate access controls and public keys being mistakenly treated as secret keys.

    Escalates the discourse from platform-specific incidents (Lovable, Moltbook) to a broad, quantified, cross-platform exposure count now covered by mainstream tech press, raising visibility with buyers and vendors alike.

    cybernews.com/news/16000-supabase-databases-exposed/
  • COMPLAINTUSER OPINIONSep 13, 2026

    New how-to/guide content aimed at vibe coders reinforces the pattern with more specific mechanics, e.g. warning that in Vite-based AI builder output (Lovable, Bolt), any variable prefixed VITE_ ships to every visitor, and that pasting keys into an AI chat to debug an error effectively leaks them into project history.

    Adds a third-plus independent sighting of the same root cause with more technical specificity, but does not introduce a new incident or vendor-side change.

    vibeanswers.com/guides/keep-api-keys-secret/
  • PRODUCTCOMPANY CLAIMSep 13, 2026

    A new paid commercial product, the "Vibe-Coded App Hardening Kit" ($79), has appeared targeting this exact failure pattern; its marketing states that the kit includes the secrets fix with the exact paste-back prompt and the manual version, plus the other nine antipatterns and a monitoring template, since hardcoded-secret findings are the pattern that shows up most, and offers a free self-declared LLM security audit as a lead-gen tool.

    Signals the discourse has matured to the point of spawning a nascent paid remediation/tooling market rather than remaining purely cautionary blog content.

    blog.redhub.ai/app-secrets-and-api-keys
  • PRODUCTCOMPANY CLAIMSep 4, 2026

    In response to the discourse, at least one AI app builder (Lovable) is cited in a social post as now including built-in dependency vulnerability scanning, and Supabase's own AI-builder marketing page continues to promote Row Level Security and its auto-generated REST/GraphQL layer as core safety features for AI-generated backends.

    vendors are beginning to respond to the security discourse with built-in scanning/RLS defaults, which could reduce the complaint's severity over time

    x.com/PrajwalTomar_/status/2041087020936966551
  • DISCOURSEUSER OPINIONSep 4, 2026

    Multiple independent first-person accounts and commentary pieces (a hosting-company blog, a Netizen security blog, and individual developer post-mortems) converge on the same failure pattern: AI coding assistants generate code that stores or embeds API keys conveniently rather than securely, leading to hardcoded secrets, client-side exposure, and permissive CORS/authorization gaps once pushed to public repos or production.

    this is now a recurring, cross-sourced complaint theme (third+ independent sighting) rather than an isolated incident, indicating the pattern has moved from niche to mainstream security discourse

    blog.netizen.net/2026/05/29/exposed-apis-leaked-keys-and-the-new-attack-surface-created-by-vibe-coding/
  • COMPLAINTFACTSep 4, 2026

    Security firm RedHunt Labs scanned sites deployed via v0.app and identified roughly 25,000 unique hardcoded secrets for popular services like OpenAI, Google, and ElevenLabs, a count that specifically excluded generic/low-entropy keys to focus on high-impact secrets.

    provides an independently measured, third-party data point (not just anecdote) on secret exposure scale in AI-generated apps

    redhuntlabs.com/blog/echoes-of-ai-exposure-thousands-of-secrets-leaking-through-vibe-coded-sites-wave-15-project-resonance/
  • DISCOURSEUSER OPINIONSep 4, 2026

    A widely circulated Medium post claimed that Moltbook, described as a platform built almost entirely on AI-generated code, leaked 1.5 million API keys, a figure also repeated in social media security checklists citing '1.5M API keys and 35K emails' leaked from a vibe-coded app.

    single large-scale incident is being used as the reference case in ongoing vibe-coding security discourse, though the underlying claim is not independently verified in a primary source

    medium.com/@hamzaashfaqchaudhary/380-000-vibe-coded-apps-are-leaking-your-data-2a691173ef78
  • COMPLAINTFACTSep 4, 2026

    A researcher-confirmed vulnerability tracked as CVE-2025-48757 was assigned after security researchers found that Lovable-generated apps were commonly connecting to Supabase without Row Level Security policies configured, exposing user data; a second researcher (Daniel Asaria at Palantir) independently reproduced the issue and extracted debt balances, home addresses, and API keys from multiple apps using a short Python script. Lovable disputes the CVE's validity and places responsibility on users.

    affects buyers evaluating Lovable/Supabase-style AI app builders for production use — RLS is not enforced by default

    www.xda-developers.com/keep-finding-vibe-coded-apps-leak-user-data/

A record of what Forge read in public about Security of generated applications — its own pages and what people wrote about it. Nothing here is a test of the product, a ranking or a score, and Forge has no relationship with this company.

Start free

Competing with Security of generated applications?

An account reads your own product beside it, every week: what it ships, what it charges, what its users complain about — each line with its source — and where your product stands against the gap. Free to start, no card.