AI coding tools are brilliant for speeding things up, but they’re not a substitute for proper security checks.
A good example surfaced recently involving Lovable, a $6.6B “vibe coding” platform that showcases apps built largely with AI. Someone tested one of their featured EdTech apps and found 16 security vulnerabilities in just a few hours, including 6 critical issues.
The problems were serious:
• 18,697 user records exposed (names, emails, roles) with no authentication
• Accounts could be deleted via a single API call with no auth
• Student grades could be modified without logging in
• Bulk email sending available to anyone
• Data from 14 enterprise institutions accessible
The most worrying part? The authentication logic was backwards. The app blocked logged-in users while allowing anonymous users through. It technically “worked”, but nobody had properly reviewed the AI-generated code.
Eventually the developer acknowledged the report and fixed the most serious issues, but it’s a perfect example of the real risk.
AI can produce working code that looks convincing but that doesn’t mean it’s secure.
The takeaway is simple: AI is an incredibly useful assistant, but the output still needs to be reviewed, tested, and understood by someone with real technical experience.
At AmbroTech, we believe technology should be built properly and securely, not just quickly. That means real review, real testing, and real accountability behind the systems people rely on.
AmbroTech
IT that works. Support that cares. 🐞💻





