CriticalSecurity & Privacy
Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web
Security researchers discovered over 5,000 AI-generated web applications hosted on popular platforms with virtually no security controls, with approximately 40% exposing sensitive corporate and personal data including medical records, financial information, and strategy documents. This represents a critical supply chain risk as organizations unknowingly leak proprietary information through poorly secured applications built with low-code/no-code AI tools, and the ease of discovery via simple search queries suggests widespread exposure. IT leaders must immediately assess their organization's use of these platforms and implement governance frameworks to prevent unauthorized data exposure through rapid application development tools.

Companies like Lovable, Base44, Replit, and Netlify use AI to let anyone build a web app in seconds—and in thousands of cases, spill highly sensitive data onto the public internet.