A security researcher disclosed that any free account on Lovable, an AI app-building platform, could read another user’s source code, database credentials, AI chat history, and customer data through just five API calls. The flaw stemmed from a February 2026 backend change that reopened a tenant-isolation gap tied to the same missing Row Level Security pattern behind an earlier Lovable vulnerability, and it went unpatched for 76 days despite being reported 48 days before public disclosure. Lovable shipped a fix within two hours of the April 20, 2026 disclosure, after initially disputing that a breach had occurred.