The open door that became a CVE
A researcher scan of Lovable-built projects found endpoints readable without logging in — names, payment status, API keys. The missing row-level-security default was assigned CVE-2025-48757, and follow-up reporting found the exposure wider still.
The reflex: Row-level security ON with explicit policies for every table the browser can reach, proven with a second, non-owner account.