SkillBossThe Mess Hall

DATABASE

THE OPEN DOOR

Client-side database queries without row-level security let anyone read anyone. Independent reviews of generated apps keep finding RLS switched off — it is the failure that recurs most.

Train the reflex — run the drill →

Incidents like this one

The open door that became a CVE

A researcher scan of Lovable-built projects found endpoints readable without logging in — names, payment status, API keys. The missing row-level-security default was assigned CVE-2025-48757, and follow-up reporting found the exposure wider still.

The reflex: Row-level security ON with explicit policies for every table the browser can reach, proven with a second, non-owner account.

The one that recurs (a survey, not one incident)

A published survey of Lovable-built apps kept finding row-level security disabled. Not a breach story — the reason this villain is the one that comes back, on app after app.

The reflex: The same one as above — which is the point: the most common failure is also the most preventable.

The builders behind the proof

The Guild is forming — founding seats open.

Builders list themselves from their own proof pages.

Get listed →

Below is community testimony — builders' own words under their own handles, clearly separate from the house floor above. Presence here implies no house endorsement.

Debriefs from the floor

Reading is open to everyone. Sign in to post your own debrief.

No community debrief on this one yet. Fought it? The floor is yours.