Security firm RedAccess has reported that AI-built applications created on popular vibe-coding platforms left sensitive corporate and personal data open to the public internet. Axios reported the findings on May 7, 2026.
RedAccess identified roughly 380,000 publicly accessible assets built on Lovable, Base44, Replit and Netlify. About 5,000 of them contained sensitive corporate data. The exposed material included medical records and patient conversations, financial information from banks, internal documents from Fortune 500 companies, clinical trial details, customer service interactions and personally identifiable information. Researchers also found phishing sites built on the platforms that impersonated Bank of America, FedEx, Trader Joe's and McDonald's.
Privacy settings on the apps defaulted to public, and many of the pages had been indexed by Google search. RedAccess CEO Dor Zvi described employees building and deploying tools for company use without permission and said the practice has no clear limit.
The platform companies disputed parts of the report. Replit CEO Amjad Masad said RedAccess gave the company only 24 hours of notice and did not share a list of affected users. A Lovable spokesperson said the reports lacked URLs or technical specifics needed for verification. Blake Brodie of Wix, which owns Base44, said RedAccess withheld the URLs and that some of the apps were set to public on purpose.
RedAccess verified examples that included shipping vessel schedules, a long-term care facility's patient conversations and school lesson recordings that contained student data. The report places the exposure with the apps' creators and default settings, and the platforms have contested how the findings were shared.
Source: Axios - https://www.axios.com/2026/05/07/loveable-replit-vibe-coding-privacy