The Register -
20 Apr 2026 23:26
A lesson in how not to respond to vulnerability reports Vibe-coding platform Lovable is pooh-poohing a researchers finding that anyone could open a free account on the service and read other users' sensitive info, including credentials, chat history, and source code. However, the companys story keeps changing: First it attributed the publicly exposed info to "intentional behavior" and "unclear documentation," then threw bug-bounty service HackerOne under the bus.
Share this Article