Sentrail
Confirmed product vulnerabilityFixed

Lovable universal account-takeover vulnerability chain

Vidoc Security disclosed a vulnerability chain involving Lovable sandbox applications and authentication/session behavior that could have enabled account takeover.

Platform
Lovable
Event date
2025-07-07
Disclosure date
2025-07-07
Affected layer
Sandbox origin, authentication, and session handling

Confirmed impact

Lovable fixed the reported chain. The research account says Lovable reviewed logs and found no untrusted exploitation or user impact.

Evidence classification

Confirmed product vulnerability. High for the technical finding: the discovering research team published reproduction details and the vendor response. This is not evidence of a real-world breach.

Remediation and status

Lovable changed the affected controls after coordinated disclosure; the research report states the issue was fixed within hours.

Sentrail analysis

Shared parent domains, cookies, browser messaging, and sandbox trust assumptions should be reviewed as one boundary. This record is classified as a product vulnerability, not an exploited incident.

What builders can learn

  • Isolate user-controlled applications from privileged product origins.
  • Constrain cross-window messaging by exact origin and expected message shape.
  • Review cookie scope and authentication redirects together.

Update history

  1. Vidoc published technical details after remediation.