An insufficient database Row-Level Security policy in...
Critical severity
Unreviewed
Published
May 30, 2025
to the GitHub Advisory Database
•
Updated May 30, 2025
Description
Published by the National Vulnerability Database
May 30, 2025
Published to the GitHub Advisory Database
May 30, 2025
Last updated
May 30, 2025
An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites.
References