Lovable universal account-takeover vulnerability chain
Vidoc Security disclosed a vulnerability chain involving Lovable sandbox applications and authentication/session behavior that could have enabled account takeover.
- Platform
- Lovable
- Event date
- 2025-07-07
- Disclosure date
- 2025-07-07
- Affected layer
- Sandbox origin, authentication, and session handling
Confirmed impact
Lovable fixed the reported chain. The research account says Lovable reviewed logs and found no untrusted exploitation or user impact.
Evidence classification
Confirmed product vulnerability. High for the technical finding: the discovering research team published reproduction details and the vendor response. This is not evidence of a real-world breach.
Remediation and status
Lovable changed the affected controls after coordinated disclosure; the research report states the issue was fixed within hours.
Sentrail analysis
Shared parent domains, cookies, browser messaging, and sandbox trust assumptions should be reviewed as one boundary. This record is classified as a product vulnerability, not an exploited incident.
What builders can learn
- Isolate user-controlled applications from privileged product origins.
- Constrain cross-window messaging by exact origin and expected message shape.
- Review cookie scope and authentication redirects together.
Update history
Vidoc published technical details after remediation.
