Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web

TL;DR AI
2 min readKey summary
Security researchers say AI-built web apps are being left publicly exposed online with little or no authentication.
RedAccess found more than 5,000 such apps, and roughly 2,000 appeared to expose sensitive data; some may even allow admin access.
The issue affects apps made with tools including Lovable, Replit, Base44, and Netlify, creating broad privacy and security risks.
Companies disputed parts of the report, but did not deny that the exposed apps were publicly reachable.
