Security researchers have identified more than 5,000 publicly accessible web apps created with AI coding tools that allegedly lack adequate security protections and authentication systems.
According to a report from wiredRedAccess researcher Dor Zvi and his team analyzed thousands of applications built using AI development platforms such as Lovable, Replit, Base44, and Netlify.
Researchers said that while many of the applications allowed anyone with a web address to access the app and its data, others required only a basic email sign-in step.
Confidential data leakage
Zvi said about 40% of the apps identified exposed sensitive information.
The report said the data leaked included medical information, financial records, corporate strategy documents, cargo records, sales information, and chatbot conversation logs containing customer names and contact details.
Some applications reportedly also allowed administrative access that allowed users to remove other administrators and gain broader control over the system.
According to the report, the researchers identified vulnerable applications through searches on Google and Bing, as many AI development tools host applications directly on their own domains rather than individual customer domains.
Concerns about AI-driven development
The report also said researchers discovered phishing websites hosted on Lovable’s domain that appeared to mimic companies such as Bank of America, Costco, FedEx, Trader Joe’s and McDonald’s.
Zvi said the rapid adoption of AI-generated applications is allowing employees to create and deploy tools without traditional development reviews or security checks.
He warned that organizations may be unintentionally exposing sensitive information through these applications without realizing the risks involved.
