Home / Incidents / May 2026

Someone finally scanned 380,000 vibe-coded apps. About 5,000 were leaking medical records and bank financials.

big oops verified Lovable base44 Replit Last verified Jul 17, 2026
TL;DR  In May 2026, Israeli cybersecurity startup RedAccess reported scanning roughly 380,000 apps built on platforms including Lovable, Base44, Replit, and Netlify. Thousands sat on the open web with no access controls, about 5,000 were actively leaking sensitive information, and roughly 40% of the vulnerable apps exposed data like medical records, bank financials, and customer chat logs. The most common root cause was a default-public setting nobody ever flipped.
Date
May 2026
Tools involved
Lovable, base44, Replit
Impact
About 5,000 of roughly 380,000 scanned apps actively leaking sensitive data; roughly 40% of vulnerable apps exposed medical, financial, or corporate records
Root cause
Default-public project settings on vibe-coding platforms; builders never flipped apps to private or added access controls

What happened

In early May 2026, Israeli cybersecurity startup RedAccess published findings from a scan of roughly 380,000 applications built on vibe-coding and no-code platforms including Lovable, Base44, Replit, and Netlify. The scan found thousands of apps deployed to the open web with no access controls at all: more than 2,000 holding sensitive corporate, operational, or personal data, and around 5,000 actively leaking sensitive information.

Roughly 40% of the vulnerable apps exposed data such as medical records, financial information, corporate strategy documents, and customer-service chat transcripts. Many granted admin access by default to anyone who reached the URL. The verified real-world exposures RedAccess cited read like a cross-section of the economy: a shipping company's vessel schedules, the status of UK clinical trials at a healthcare firm, internal financials from a Brazilian bank, and customer chat logs from a British furniture retailer.

The root cause RedAccess identified was structural rather than exotic. Several major vibe-coding platforms make new projects reachable by anyone with the URL unless the builder explicitly flips them to private. That step never surfaces in the typical workflow of describing the app, accepting what the AI produces, and moving on, and many of the builders are non-technical, so nobody ever flips it.

The research was covered by Axios, WIRED, VentureBeat, and The Hacker News, which examined the roughly 2,000 corporate-app subset across the roughly 380,000 publicly accessible assets. It stands as a category-defining measurement of how much data vibe-coded apps are exposing in aggregate.

Impact

The scale is the story: out of roughly 380,000 scanned apps, around 5,000 were actively leaking sensitive information and more than 2,000 held sensitive corporate, operational, or personal data with no access controls. Roughly 40% of the vulnerable apps exposed high-consequence data, including medical records, financial information, corporate strategy documents, and customer-service transcripts. The confirmed examples spanned a shipping company's vessel schedules, UK clinical trial statuses at a healthcare firm, a Brazilian bank's internal financials, and a British furniture retailer's customer chat logs, and in many cases anyone with the URL got admin access by default.

Root cause

This was not a sophisticated attack; it was a default. Several major vibe-coding platforms ship new projects public, reachable by anyone who has or guesses the URL, unless the builder explicitly switches them to private. The people building these apps are often non-technical, the describe-accept-ship workflow never surfaces the visibility setting, and the AI does not volunteer that the app it just built is readable by the entire internet. Multiply one skipped checkbox by hundreds of thousands of apps and you get about 5,000 live leaks.

How to not be this entry

Tools that actually fix this

Recommended because they address the failure mode above, not because of the payout. Some are affiliate links; see how we choose.

Frequently asked questions

What did the RedAccess scan of vibe-coded apps find?

In May 2026, RedAccess scanned roughly 380,000 apps built on vibe-coding and no-code platforms including Lovable, Base44, Replit, and Netlify. It found thousands deployed with no access controls, more than 2,000 holding sensitive corporate, operational, or personal data, and around 5,000 actively leaking sensitive information, with roughly 40% of the vulnerable apps exposing data like medical records and financial information.

What kinds of data were vibe-coded apps leaking?

The RedAccess research found vibe-coded apps exposing medical records, financial information, corporate strategy documents, and customer-service chat transcripts. Verified examples included a shipping company's vessel schedules, the status of UK clinical trials at a healthcare firm, internal financials from a Brazilian bank, and customer chat logs from a British furniture retailer. Many of the exposed apps granted admin access by default to anyone who reached the URL.

Why were so many vibe-coded apps publicly exposed?

The key root cause RedAccess identified was default-public project settings: several major vibe-coding platforms make new projects reachable by anyone with the URL unless the builder explicitly flips them to private. That step never surfaces in the typical describe-it, accept-it, ship-it workflow, and many builders on these platforms are non-technical, so the setting simply never gets changed.

Which platforms were included in the RedAccess scan?

RedAccess scanned roughly 380,000 applications built on vibe-coding and no-code platforms including Lovable, Base44, Replit, and Netlify. The findings were covered by Axios, WIRED, VentureBeat, and The Hacker News, which focused on the roughly 2,000 exposed corporate apps within the larger set of publicly accessible assets.

How do I check whether my vibe-coded app is exposed?

Start with your platform's project visibility setting and confirm the app is actually private, since several vibe-coding platforms default new projects to public. Then open your app's URLs in a logged-out browser and try to reach data views and admin pages directly; if anything sensitive loads without a login, you are exposed. Finally, verify that every backend endpoint requires authentication rather than relying on the URL staying secret.

Sources

Related error guides

The Vibe Oops briefing

One email when something ships to production that should not have. New incidents, new error guides, no filler.