Skip to main content
Live
Main content

Thousands of Vibe-Coded Apps Leak Medical Records and Corporate Strategy Decks

Red Access scanned 380,000 apps built on Replit, Lovable and Base44, finding roughly 2,000 leaking sensitive data with no authentication.

Jaeden Schafer
Editor in Chief · · 4 min read
Thousands of Vibe-Coded Apps Leak Medical Records and Corporate Strategy Decks
AICD
AI Chat Podcast

Anthropic's Launches Claude "Dreaming", Buys SpaceX Compute

Thousands of applications built with AI vibe-coding tools are leaking sensitive customer data, including medical conversations and internal corporate strategy decks, according to new research from Israeli security firm Red Access. The firm scanned roughly 380,000 publicly accessible apps deployed on Replit, Lovable, Base44 and Netlify, and found that about 5,000 had no authentication in place at all.

Of those exposed apps, around 2,000 were actively serving sensitive data to anyone who guessed or stumbled onto the URL. "So about 40% of those or about 2000 apps were exposing sensitive data to anyone who happened to find the URL," Jaeden Schafer said on the podcast, summarising the scale of the problem facing the new generation of natural-language app builders.

The categories of data Red Access surfaced read like a worst-case compliance audit. Researchers found conversations between doctors and patients at a long-term care facility for children, a security company's own incident response data, a school app containing lesson recordings and student records, a vacation planner exposing customer details, customer chatbot transcripts and internal corporate strategy presentations. In each case, possession of a URL was effectively the only access control.

Key facts

  • 01Israeli security firm Red Access scanned 380,000 apps built on Replit, Lovable, Base44 and Netlify and found roughly 2,000 leaking sensitive data.
  • 02About 40% of the apps Red Access flagged had no authentication at all, exposing data to anyone with the URL.
  • 03Leaked material included doctor-patient conversations at a children's long-term care facility, school records, customer chatbot logs and internal corporate strategy decks.
  • 04Replit pushed back on the disclosure, saying Red Access gave the platforms only 24 hours before going to the press.

The platforms named in the report are not all reacting the same way. Replit is publicly pushing back, arguing the disclosure window was too tight. "Red Access only gave them 24 hours before going to the press and like he's I guess it's kind of true," Schafer said, noting Replit's complaint that vendors were not given a realistic chance to patch before the findings hit the media.

There's a huge difference between AI building you a working app and AI building you a secure app that isn't going to leak your data.
Jaeden Schafer

Base44 appears to be moving more quietly toward a default-private posture. Schafer, a Base44 user, said he received notice that older projects on the platform had been switched to private en masse, with public exposure now requiring users to actively re-enable sharing and clear additional security checks. Lovable went through a similar episode recently, in which projects created before November 2025 were found to carry security flaws that newer builds did not.

The pattern points to a structural weakness in how the first wave of vibe-coded software was shipped. Models were optimised to produce something that runs, not something that withstands a hostile internet, and authentication was often left as an exercise for a non-technical user who did not know to ask. "I think there's a huge difference between AI building you a working app and AI building you a secure app that isn't going to leak your data," Schafer said.

For platforms, the cleanup playbook is converging on the same move: revert legacy projects to private by default, and force users to opt back into public deployment only after addressing the security gaps the model failed to handle. That is a meaningful shift for tools whose original pitch was that anyone could ship a live app in an afternoon without touching auth or backend code.

The Red Access findings are likely to sharpen scrutiny of the vibe-coding category just as it goes mainstream with non-developer users storing real customer information. Healthcare conversations, school records and corporate decks sitting behind a guessable URL are precisely the data classes that draw regulators, and the next phase of competition between Replit, Lovable and Base44 may be decided less by how fast they generate code than by how aggressively they default it to safe.

Related · from this week
Red Access Finds 2,000 Vibe-Coded Apps Leaking Medical and Corporate Data
Jaeden Schafer · 4 min read →
ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Red Access Finds 2,000 Vibe-Coded Apps Leaking Medical and Corporate Data
Security

Red Access Finds 2,000 Vibe-Coded Apps Leaking Medical and Corporate Data

Israeli security firm scanned 380,000 apps built on Lovable, Replit and Base44 and found roughly 2,000 with no authentication at all.

Jaeden Schafer4 min read
RedAccess finds 5,000 vibe-coded apps from Lovable, Replit and Base44 leaking data
Security

RedAccess finds 5,000 vibe-coded apps from Lovable, Replit and Base44 leaking data

Roughly 2,000 of the AI-built apps exposed medical records, customer chat logs and corporate strategy decks to anyone with the URL.

Jaeden Schafer5 min read
Lovable in talks to raise $300M at $13.2B, doubling its December valuation
Business

Lovable in talks to raise $300M at $13.2B, doubling its December valuation

Menlo Ventures is expected to lead the round for the Swedish vibe-coding startup, which hit $500M ARR in June.

Jaeden Schafer4 min read