Skip to main content
Live
Main content

Red Access Finds 2,000 Vibe-Coded Apps Leaking Medical and Corporate Data

Israeli security firm scanned 380,000 apps built on Lovable, Replit and Base44 and found roughly 2,000 with no authentication at all.

Jaeden Schafer
Editor in Chief · · 4 min read
Red Access Finds 2,000 Vibe-Coded Apps Leaking Medical and Corporate Data
AICD
AI Chat Podcast

Anthropic's Launches Claude "Dreaming", Buys SpaceX Compute

Israeli security research firm Red Access says it found thousands of apps built with AI coding tools leaking sensitive customer data, in the latest sign that the vibe-coding boom is racing ahead of basic application security. The firm scanned 380,000 publicly accessible apps built on Lovable, Replit, Base44 and Netlify, and reported that roughly 5,000 of them shipped with no authentication at all.

Of that group, about 2,000 apps were actively exposing data to anyone who stumbled onto the URL. "So about 40% of those or about 2000 apps were exposing sensitive data to anyone who happened to find the URL," Jaeden Schafer said on the AI Chat Daily podcast, walking through the findings.

The categories of data Red Access surfaced read like a worst-case compliance audit. Researchers found conversations between doctors and patients at a long-term care facility for children, a school app containing lesson recordings and student records, a vacation planning tool with customer details, customer chatbot logs and internal corporate strategy decks. In one moment of irony, they also pulled up a security company's own incident response data sitting unprotected on the open web.

Key facts

  • 01Israeli security firm Red Access scanned 380,000 publicly accessible apps built on Lovable, Replit, Base44 and Netlify and found about 5,000 with no authentication.
  • 02Roughly 2,000 of those apps were actively exposing sensitive data to anyone with the URL, including doctor-patient conversations at a long-term care facility for children.
  • 03Exposed material also included a security company's incident response data, school lesson recordings and student records, customer chatbot logs and internal corporate strategy decks.
  • 04Base44 has retroactively made all projects created before a certain date private by default, while Replit is pushing back on Red Access for giving it only 24 hours before going public.

The vendors are reacting unevenly. Replit is pushing back on the disclosure timeline, with its chief executive arguing that Red Access only gave the company 24 hours before taking the findings to the press. Schafer said the complaint has some merit, noting Replit's position is essentially "why don't you guys give us more time to like fix it before you went live with it."

there's a huge difference between AI building you a working app and AI building you a secure app that isn't going to leak your data.
Jaeden Schafer

Base44 appears to have moved more aggressively. Schafer, who holds a Base44 account, said he received notice that older projects had been quietly locked down. "all of the all projects on base 44 made before a certain date were automatically made private If you want to go make it public again, you can go do it, but you got to do like some security stuff," he said, describing the platform's response.

The pattern of legacy projects carrying the worst exposure is showing up across the category. Lovable hit a similar wall earlier, where projects created before November 2025 carried security gaps that newer builds did not. The fix industry-wide is converging on the same answer: flip older user-generated apps back to private by default, and require the owner to clear a security checklist before re-exposing them to the public internet.

The episode highlights the gap between what AI coding agents are good at today and what production software actually requires. "there's a huge difference between AI building you a working app and AI building you a secure app that isn't going to leak your data," Schafer said, framing authentication and access control as the next problem the vibe-coding platforms have to solve before regulated data ever touches their tools.

For now the practical implication for builders is straightforward. Anyone who shipped a Lovable, Replit or Base44 project earlier this year — particularly one handling health, education or internal corporate information — should assume it was scanned, check whether the host platform has already forced it private, and treat re-publication as a security exercise rather than a one-click toggle.

Related · from this week
Thousands of Vibe-Coded Apps Leak Medical Records and Corporate Strategy Decks
Jaeden Schafer · 4 min read →
ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Thousands of Vibe-Coded Apps Leak Medical Records and Corporate Strategy Decks
Security

Thousands of Vibe-Coded Apps Leak Medical Records and Corporate Strategy Decks

Red Access scanned 380,000 apps built on Replit, Lovable and Base44, finding roughly 2,000 leaking sensitive data with no authentication.

Jaeden Schafer4 min read
RedAccess finds 5,000 vibe-coded apps from Lovable, Replit and Base44 leaking data
Security

RedAccess finds 5,000 vibe-coded apps from Lovable, Replit and Base44 leaking data

Roughly 2,000 of the AI-built apps exposed medical records, customer chat logs and corporate strategy decks to anyone with the URL.

Jaeden Schafer5 min read
Lovable in talks to raise $300M at $13.2B, doubling its December valuation
Business

Lovable in talks to raise $300M at $13.2B, doubling its December valuation

Menlo Ventures is expected to lead the round for the Swedish vibe-coding startup, which hit $500M ARR in June.

Jaeden Schafer4 min read