Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web
Mass Data Exposure Through AI-Generated Web Apps
As AI tools increasingly automate app development, a sweeping security risk has emerged. A recent investigation by cybersecurity researchers at RedAccess revealed that thousands of web applications created with popular AI coding platforms—including Lovable, Replit, Base44, and Netlify—unknowingly make sensitive information available to anyone online.
The Scope of the Problem
The researchers found over 5,000 web apps with minimal or no security measures: most were accessible to anyone with their URL, and some required only trivial barriers like generic email sign-ins. Alarmingly, around 40% of these apps exposed confidential data such as medical records, financial information, strategy presentations, customer chat logs, and much more. In several instances, control over admin privileges and further system access was at risk.
How Were the Apps Discovered?
Tools like Lovable, Replit, Base44, and Netlify host users’ apps on their own domains, enabling simple web searches to locate thousands of exposed projects. Many apps contained what appeared to be real, sensitive content, such as doctor's schedules, corporate plans, sales records, and shipping logs. There were even instances of phishing sites mimicking major corporations created with these AI tools.
Industry Response and Accountability
The AI coding companies generally responded by emphasizing that security configuration is the responsibility of the users, not the platforms. They highlighted that options for privacy and authentication are available—but app creators must actively enable these settings. This points to the growing challenge as non-technical users rapidly deploy applications without adequate security awareness or vetting processes.
The Bigger Picture
Experts compare this issue to earlier waves of data leaks caused by misconfigured cloud storage. The concern is that easy-to-use AI tools let people outside traditional IT teams launch applications, bypassing typical security reviews. As organizations rush to empower employees with fast app development, they may be exposing themselves to significant data breaches.
Read the full original article by Andy Greenberg on WIRED for an in-depth analysis.