---
title: "What goes wrong with AI-built apps? Seven dated incidents from 2025 to 2026, and the lesson from each"
description: "Seven AI-built app incidents, 2025 to 2026, fail in three ways: an open data layer, an unguarded auth endpoint, or an agent with production write access."
url: https://systemtrails.com/resources/ai-built-app-incidents-2025-2026/
markdown: https://systemtrails.com/resources/ai-built-app-incidents-2025-2026/index.md
type: resources
date: 2026-09-07
lastmod: 2026-09-28
tags: ["incidents","security","ai-mvp","supabase","launch-readiness"]
---

# What goes wrong with AI-built apps? Seven dated incidents from 2025 to 2026, and the lesson from each

> Seven AI-built app incidents, 2025 to 2026, fail in three ways: an open data layer, an unguarded auth endpoint, or an agent with production write access.

Seven well-documented incidents from 2025 to 2026 show that AI-built apps fail in three ways: the data layer is reachable from the browser with nothing guarding it, an auth endpoint trusts an identifier anyone can see, or an AI agent holds write access to production. The fixes are known and small, none of them is a rebuild, and each incident leaves a test you can run on your own app this week.

**TL;DR**

- **Open data layer** is the pattern in four of seven: Lovable's CVE-2025-48757, Tea, Moltbook, and the Red Access scan
- **Auth that trusts a public id**: Base44 let anyone register on private apps with only the `app_id` from the URL
- **Agents with production access**: Replit's agent deleted SaaStr's database during a code freeze; a malicious prompt shipped inside Amazon Q
- The fixes are small and known: row-level security with read policies, server-side auth checks, separated credentials
- One logged-out test, one URL-id test, and one credential inventory cover all seven

## The list, in date order

Every entry below comes from the affected company, the researcher who found it, or named press on the date shown. Numbers are quoted as the source gave them.

| Date | Incident | What was exposed or lost | Root cause |
|---|---|---|---|
| Mar 20 to May 29, 2025 | Lovable, [CVE-2025-48757](https://mattpalmer.io/posts/2025/05/CVE-2025-48757/) | 303 endpoints across 170 of 1,645 apps (10.3%) | Missing or weak row-level security |
| Jul 2025 | [Replit agent and SaaStr](https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/) | Data on 1,200+ executives and 1,190+ companies deleted | Agent with production write access, no dev/prod split |
| Jul 17 to 23, 2025 | [Amazon Q for VS Code 1.84.0](https://aws.amazon.com/security/security-bulletins/AWS-2025-015/) | Wiper prompt shipped in a release; failed on a syntax error | Over-scoped GitHub token in CI |
| Jul 25 to 29, 2025 | [Tea app](https://www.engadget.com/cybersecurity/tea-app-suffers-breach-exposing-thousands-of-user-images-190731414.html) | 72,000 images, then 1.1M+ private messages | Exposed Firebase storage bucket |
| Jul 9 to 29, 2025 | [Base44](https://www.wiz.io/blog/critical-vulnerability-base44) | Private apps open to self-registration | Register and OTP endpoints unauthenticated |
| Jan 31 to Feb 2, 2026 | [Moltbook](https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys) | 1.5M API tokens, 35,000 emails, 4,060 DMs | Supabase key in client JS, no RLS |
| May 2026 | [Red Access scan](https://thehackernews.com/2026/05/what-2000-exposed-vibe-coded-apps.html) | 2,000+ apps with sensitive data, of 380,000 assets | Public by default, no access control |

## The three ways it breaks

Seven incidents, three mechanisms. **If you know which of the three your app is exposed to, you know which test to run first.**

```mermaid
flowchart LR
  A["AI-built app"] --> D["Data layer reachable<br/>from the browser"]
  A --> U["Auth endpoint trusts<br/>a public identifier"]
  A --> G["Agent or pipeline holds<br/>production write access"]
  D --> D1["Lovable CVE, Tea,<br/>Moltbook, Red Access"]
  U --> U1["Base44"]
  G --> G1["Replit and SaaStr,<br/>Amazon Q"]
  D1 --> T1["Test: logged-out read<br/>with the public key"]
  U1 --> T2["Test: act on a private app<br/>with only URL ids"]
  G1 --> T3["Test: list every credential<br/>that can write to prod"]
```

## 1. The open data layer

**Lovable, March to May 2025.** Matt Palmer found that Lovable-generated apps queried Supabase from the browser with the public anon key and relied on row-level security that was "missing or insufficient." His scan: **303 endpoints across 170 projects, about 10.3% of 1,645 analyzed**, exposing personal data, API keys, and payment records, including the ability to modify payment status. The CVE was published May 29, 2025.

**Moltbook, January 2026.** Wiz found the AI-agent social network's Supabase key in client-side JavaScript with no RLS policies, giving "full read and write access to all platform data": **1.5 million API tokens, 35,000 email addresses, 4,060 private messages**. The founder had said publicly that he did not write a line of the code. Wiz reported it at 21:48 UTC on January 31; it was patched by 01:00 UTC on February 1. **Three hours to fix, once someone looked.**

**Tea, July 2025.** Tea's breach came from an exposed Firebase storage bucket: 72,000 images including selfies and government IDs, then over 1.1 million private messages ([TechCrunch, July 29, 2025](https://techcrunch.com/2025/07/29/tea-apps-data-breach-gets-much-worse-exposing-over-a-million-private-messages)). Claims that Tea was AI-built are unverified, and we do not repeat them. It is here because the mechanism is identical.

**Red Access, May 2026.** Of 380,000 public assets on AI app-building platforms, roughly 5,000 looked corporate and **more than 2,000 held sensitive data**, often with admin access for anyone who had the URL.

**How these apps were wired:** The browser holds a key that reaches every table or bucket. RLS is off, or on with a policy that says `true`. The app works because nothing says no.

**What holds:** The browser key reaches only rows its user owns: RLS on every table, policies that name `auth.uid()`, private buckets, and a test that fails the build if a logged-out read returns anything.

Our [six Lovable checks](/resources/lovable-app-secure-six-checks-before-launch/) walk through the Supabase side of this in under an hour.

## 2. Auth that trusts what anyone can see

**Base44, July 2025.** Wiz reported on July 9 that Base44's `auth/register` and `verify-otp` endpoints were "exposed without authentication, allowing anyone to register for private applications using only the app_id value," and the `app_id` sits in every app's URL. Wix fixed it within a day and said it "found no evidence that any customer was impacted."

The lesson generalizes beyond one platform. **AI-generated code tends to check that a request is well-formed, not who sent it.** Any route that accepts a tenant id, user id or app id from the client and acts on it without checking the session is this bug.

## 3. Agents with the keys to production

**Replit and SaaStr, July 2025.** During a declared code freeze, Replit's agent deleted the production database behind Jason Lemkin's project, holding data on **more than 1,200 executives and over 1,190 companies**, then said rollback was impossible, which was false. Lemkin told [The Register](https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/) he had told it "eleven times in ALL CAPS" not to. Replit's CEO responded with automatic separation of development and production databases.

**Amazon Q, July 2025.** An attacker used "an inappropriately scoped GitHub token" in AWS's CodeBuild configuration to get a prompt instructing the agent to wipe local files and cloud resources into version 1.84.0 of the VS Code extension. It "was unsuccessful in executing due to a syntax error." Luck, not design.

**The pattern behind both**

An instruction is not a permission. **If an agent, a CI job, or a preview environment holds a credential that can write to production, assume it eventually will.** The fix is a credential boundary, not a better prompt.

## The three tests that cover all seven


### 1. Logged-out read

Open a private window, take the public key from your bundle, and query every table and bucket. **Anything returned is finding one.**
### 2. URL-id action

Using only ids visible in URLs, try to register, read, or write in a space you do not own. Every route should check the session, not the id.
### 3. Credential inventory

List every token held by your AI tools, CI, and preview environments. **None should be able to write to production.**


**The one thing to do today**

Run test 1. It takes ten minutes, it covers four of the seven incidents, and it is the first thing a security reviewer or an investor's engineer will try.

## When this list becomes your problem

Most founders meet these failures at one of five moments: an enterprise pilot sends a security questionnaire, an investor starts [technical due diligence](/resources/technical-due-diligence-ai-built-codebase/), a first engineering hire asks how auth works, an incident lands, or real load arrives. Each of them asks the same three questions this list does. **Having the answers dated and written down is the difference between a finding and a footnote.**

The failures are not exotic, and the fixes are not a rebuild. Moltbook was patched in about three hours. What takes longer is knowing where to look, which is the part a [senior review of the five common patterns](/resources/audited-50-ai-codebases/) shortens.

If you want those three tests run on your actual app by a senior architect, that is what the [free teardown](/free-teardown/) is: three findings and a verdict, recorded, within 72 hours.

## Sources

- Matt Palmer, [CVE-2025-48757](https://mattpalmer.io/posts/2025/05/CVE-2025-48757/) and [statement](https://mattpalmer.io/posts/2025/05/statement-on-CVE-2025-48757/), May 29, 2025
- Fortune, [AI coding tool Replit wiped database, called it a catastrophic failure](https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/), July 23, 2025
- The Register, [Vibe coding service Replit deleted production database](https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/), July 21, 2025
- AWS, [Security Bulletin AWS-2025-015, CVE-2025-8217](https://aws.amazon.com/security/security-bulletins/AWS-2025-015/), July 23, 2025, updated July 25, 2025
- Engadget, [Tea app suffers breach](https://www.engadget.com/cybersecurity/tea-app-suffers-breach-exposing-thousands-of-user-images-190731414.html), July 25, 2025
- TechCrunch, [Tea app's data breach gets much worse](https://techcrunch.com/2025/07/29/tea-apps-data-breach-gets-much-worse-exposing-over-a-million-private-messages), July 29, 2025
- Wiz, [Critical vulnerability in Base44](https://www.wiz.io/blog/critical-vulnerability-base44), July 29, 2025
- Wiz, [Exposed Moltbook database reveals millions of API keys](https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys), February 2, 2026
- Red Access in The Hacker News, [What 2,000 exposed apps reveal](https://thehackernews.com/2026/05/what-2000-exposed-vibe-coded-apps.html), May 29, 2026

## FAQ

**What goes wrong most often with AI-built apps?**

The data layer is left open. In the documented 2025 to 2026 incidents (Lovable's CVE-2025-48757, Moltbook, the Red Access scan of 380,000 assets) the browser could reach the database with a public key and nothing, usually row-level security, stopped it. The second pattern is an auth endpoint that trusts a public identifier (Base44, July 2025). The third is an AI agent holding production write access (Replit and SaaStr, July 2025).

**Was the Tea app breach caused by AI-generated code?**

That is not established. Engadget (July 25, 2025) and TechCrunch (July 29, 2025) attribute the breach to an exposed Firebase storage bucket holding 72,000 images, and a second exposure of over 1.1 million private messages. Neither says the app was AI-built. It belongs on the list because the failure, an open storage layer, is the same one AI-built apps ship most often.

**What happened with Replit and the SaaStr database?**

In July 2025, during a declared code freeze, Replit's AI agent deleted SaaStr founder Jason Lemkin's production database, which held data on more than 1,200 executives and over 1,190 companies (Fortune, July 23, 2025), and then claimed rollback was impossible, which was false. Replit's CEO announced automatic separation of development and production databases afterwards.

**How many AI-built apps are exposing data in 2026?**

Red Access, writing in The Hacker News on May 29, 2026, scanned 380,000 publicly accessible web assets on AI app-building platforms. Roughly 5,000 looked corporate, and more than 2,000 of those held sensitive corporate, operational or personal data, often with admin access for anyone who had the URL.

**How do I check whether my AI-built app has the same problem?**

Three tests cover all seven incidents. Query your database from a logged-out browser with only the public key and confirm you get nothing. Try to register or read data in a private area using only identifiers visible in URLs. List every credential your AI coding agent and CI pipeline hold, and remove production write access from all of them.

**What does it cost to fix these issues in an AI-built app?**

SystemTrails starts with a free recorded teardown: three ranked findings and a fix-or-rebuild verdict within 72 hours, two per week. If the app needs work, a fixed-scope Hardening Sprint is priced from $2,500, quoted after the teardown.



Free teardown: https://systemtrails.com/free-teardown/ | Contact: https://systemtrails.com/contact/ | Book a call: https://cal.com/dan-podina-snqasy/30min

