CVE-2025-48757 is an incorrect-authorization vulnerability affecting database Row-Level Security (RLS) policies in sites generated with Lovable through 2025-04-15. Insufficient RLS policies can leave arbitrary database tables accessible to unauthenticated remote parties, permitting data reads and writes. Lovable disputes the CVE characterization, stating that individual platform customers are responsible for securing their applications' data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 5 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A widespread insecure-configuration issue affecting Supabase databases created by Lovable, in which missing or inadequate Row Level Security (RLS) controls could allow unauthenticated or unauthorized querying of database data.
A critical incorrect-authorization vulnerability affecting Lovable-generated applications backed by Supabase. Missing Row Level Security (RLS) policies can leave database tables accessible through the exposed Supabase URL and anonymous key, allowing unauthenticated reads and writes.
A critical vulnerability in Lovable's implementation of Row Level Security (CVE-2025-48757) allows remote unauthenticated attackers to read or write arbitrary database tables, exposing sensitive user data and enabling data injection.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.