CVE-2025-48757 explained: the Lovable Row Level Security vulnerability and what it teaches
Short answer
CVE-2025-48757, published May 30, 2025, describes insufficient Row Level Security policies in apps generated by Lovable through April 15, 2025, allowing remote unauthenticated attackers to read or write arbitrary database tables. It is rated CVSS 3.1 9.3 (Critical) and classified as CWE-863, Incorrect Authorization. Lovable disputes it, arguing each customer is responsible for protecting their application’s data. Whatever the attribution, the bug class is current: tables reachable with the public Supabase key and protected by missing or permissive RLS.
Last updated · Sekrd Research
- CVE: CVE-2025-48757, published 2025-05-30.
- Affected: Lovable-generated sites, versions through 2025-04-15.
- Severity: CVSS 3.1 base score 9.3, Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).
- Weakness: CWE-863, Incorrect Authorization.
- Status: disputed by the vendor (customer responsibility for data protection).
What the CVE describes
The record states that an insufficient database Row-Level Security policy in Lovable allowed remote, unauthenticated attackers to read or write arbitrary database tables of generated sites. The CVSS vector explains the score: reachable over the network, low complexity, no privileges and no user interaction required, with a changed scope and high confidentiality impact.
The research behind it, published by Matt Palmer, showed that generated apps queried Supabase directly from the browser with the public key, and that the tables behind those queries were either missing RLS or protected by policies that did not restrict rows to their owner.
Why it is disputed — and why that does not matter for you
Lovable’s position, recorded in the CVE, is that each customer accepts responsibility for protecting their application’s data. That is a debate about who owns the bug. For anyone running an app built this way, the question is only whether their own tables have the same weakness — and many still do: UpGuard reported 16,326 publicly readable Supabase databases in September 2026.
The bug class in one sentence
A browser-held public key plus a table without effective Row Level Security equals a public table.
Checks that prevent it
-- Tables with RLS off
select tablename from pg_tables
where schemaname = 'public' and rowsecurity = false;
-- Policies that allow everyone
select tablename, policyname, cmd from pg_policies
where schemaname = 'public' and (qual = 'true' or with_check = 'true');
-- Policies that never reference the caller
select tablename, policyname, qual from pg_policies
where schemaname = 'public' and qual not ilike '%auth.uid()%';
The last query is a heuristic: a policy on user data that never mentions auth.uid() usually does not restrict rows to their owner. Review each result by hand.
What changed since 2025
- Lovable now runs a Quick Scan at publish that checks RLS gaps and database access rules.
- Supabase stopped exposing new tables to the Data API automatically: default for new projects since May 30, 2026, enforced on existing projects from October 30, 2026.
- Neither change fixes tables that are already exposed. Those need the checks above.
Frequently asked questions
What is CVE-2025-48757?
A CVE published on May 30, 2025 describing insufficient Row Level Security policies in Lovable-generated sites through April 15, 2025, allowing unauthenticated attackers to read or write database tables. It is rated CVSS 3.1 9.3 Critical, CWE-863 Incorrect Authorization, and disputed by Lovable.
Is CVE-2025-48757 fixed?
The CVE covers versions through April 15, 2025 and Lovable has since added RLS checks to its publish-time Quick Scan. Apps generated earlier, or apps whose RLS was later loosened, can still be affected and should be checked directly in the database.
How do I check my app for the CVE-2025-48757 weakness?
Query pg_tables for public tables with rowsecurity = false, query pg_policies for policies whose condition is true, and test a table with only the publishable key while signed out.
Sources
Don't ship until you're sekrd
Run a free scan to find the vulnerabilities your AI missed.
Scan Your App Free