Security firm RedAccess says it found more than 5,000 vibe-coded web applications built on Lovable, Replit, Base44 and Netlify that have virtually no authentication, and that close to 2,000 of them are leaking private data to anyone who types the URL into a browser. Roughly 40% of the 5,000 apps exposed sensitive material, according to cofounder Dor Zvi, including medical records, financial data, corporate strategy decks and full chatbot conversation logs with named customers. The findings were shared with WIRED on May 7, 2026.
Zvi's team didn't need exotic tooling. Because Lovable, Replit, Base44 and Netlify all let users host apps on the AI vendors' own domains, RedAccess pulled the inventory with plain Google and Bing searches scoped to those domains. From there, the researchers sorted apps by whether they required any login at all — and many didn't, or accepted any email address as a credential.
The exposed apps screenshotted for WIRED included what appeared to be a hospital's work assignments with personally identifiable doctor information, a retailer's full chatbot transcripts with customer names and contact details, a shipping firm's cargo records, and a go-to-market strategy presentation from another company. In some cases Zvi says he was able to gain administrative privileges over the underlying systems and remove other admins.
Key facts
- 01RedAccess identified 5,000 vibe-coded web apps from Lovable, Replit, Base44 and Netlify with virtually no authentication.
- 02About 40% of those apps exposed sensitive data, including medical, financial and corporate strategy documents.
- 03Close to 2,000 apps revealed private data viewable to anyone who guessed the URL.
- 04Lovable's domain hosted phishing sites impersonating Bank of America, Costco, FedEx, Trader Joe's and McDonald's.
- 05Replit CEO Amjad Masad said public apps being accessible on the internet is expected behavior.
Lovable's domain also hosted what looked like a wave of phishing kits. RedAccess flagged sites impersonating Bank of America, Costco, FedEx, Trader Joe's and McDonald's that appeared to have been built with Lovable's tool and left running on its infrastructure.
“Around 40% of the 5,000 exposed apps leaked sensitive data, and close to 2,000 revealed private records ranging from hospital staffing to customer chat logs.”— Jaeden Schafer
Three of the four vendors pushed back when contacted. Replit CEO Amjad Masad wrote on X that "Replit allows users to choose whether apps are public or private. Public apps being accessible on the internet is expected behavior. Privacy settings can be changed at any time with a single click." Netlify did not respond.
A Lovable spokesperson said the company "takes reports of exposed data and phishing sites seriously" and is treating the matter as ongoing, while adding that "how an app is configured is ultimately the creator's responsibility." Blake Brodie, head of PR at Base44 parent Wix, said Base44 ships access controls and visibility settings, and that "where applications were publicly accessible, that reflects a user configuration choice, not a platform vulnerability." Brodie also said it is "trivially easy to fabricate applications that appear to contain real user data" and disputed that RedAccess shared verified examples — a point RedAccess rejects, noting it contacted dozens of app owners directly and that several Base44 users thanked the researchers and pulled their apps offline.
Independent security researcher Joel Margolis, who recently uncovered an AI chat toy that exposed 50,000 conversations with children on a near-unsecured site, says the underlying pattern matches what he sees regularly. "Somebody from a marketing team wants to create a website. They're not an engineer and they probably have little to no security background or knowledge," Margolis said. AI coding tools, he added, "do what you ask them to do. And unless you ask them to do it securely, they're not going to go out of their way to do that."
There are reasons to read RedAccess's count cautiously. As Margolis notes, data inside a vibe-coded app may be placeholder content or a throwaway proof of concept, and Wix said two examples WIRED shared with Base44 looked like test sites or AI-generated dummy data. WIRED could not independently confirm that every leaked record was real. Zvi counters that the 5,000 apps reflect only those hosted on the AI vendors' own domains — apps deployed to customer-owned domains aren't in the sample, and likely number in the thousands more.
Zvi compares the moment to the long tail of Amazon S3 bucket leaks that hit Verizon and World Wrestling Entertainment, where misconfigured cloud storage spilled corporate data for years and the industry split blame between customers and Amazon's confusing defaults. The vibe-coding platforms are following the same script: the controls exist, but the defaults and the audience guarantee the failure mode.
The deeper issue is org-chart, not product. "Anyone from your company at any moment can generate an app, and this is not going through any development cycle or any security check," Zvi said. "People can just start using it in production without asking anyone. And they do."
Vibe-coding's pitch — anyone in the company can ship a working web app in minutes — is also its security model's biggest problem. Lovable, Replit, Base44 and Netlify are now distribution channels for production software written by people who have never been near a code review, and the platforms' insistence that visibility is the user's job is the same defense Amazon offered a decade ago. That argument lost then, and the regulatory exposure for the AI coding category is going to look a lot like the S3 era, only faster and with more PII inside.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




