Thousands of Vibe-Coded Apps Expose Corporate and Personal Data on the Open Web 07.05.2026

Security researcher Dor Zvi and his team at RedAccess have identified over 5,000 web applications created using AI coding tools like Lovable, Replit, Base44, and Netlify that exhibit virtually no security, exposing sensitive corporate and personal data. These applications, often hosted on the AI companies' domains, allow access to data such as medical records, financial information, corporate strategy documents, and customer chat logs simply by finding their web URLs. Approximately 40 percent of these apps are estimated to expose such sensitive information. The AI companies, while acknowledging users' responsibility for security configurations, have stated they are investigating the findings, with some pushing back on the extent of the researchers' disclosures. The situation is compared to previous data exposure epidemics caused by misconfigured cloud storage.





















