Don’t be fooled into thinking AI can build apps.

20 March 2026

Written by

Coby Ambrose

AI coding tools are brilliant for speeding things up, but they’re not a substitute for proper security checks.

A good example surfaced recently involving Lovable, a $6.6B “vibe coding” platform that showcases apps built largely with AI. Someone tested one of their featured EdTech apps and found 16 security vulnerabilities in just a few hours, including 6 critical issues.

The problems were serious:

18,697 user records exposed (names, emails, roles) with no authentication
Accounts could be deleted via a single API call with no auth
Student grades could be modified without logging in
Bulk email sending available to anyone
• Data from 14 enterprise institutions accessible

The most worrying part? The authentication logic was backwards. The app blocked logged-in users while allowing anonymous users through. It technically “worked”, but nobody had properly reviewed the AI-generated code.

Eventually the developer acknowledged the report and fixed the most serious issues, but it’s a perfect example of the real risk.

AI can produce working code that looks convincing but that doesn’t mean it’s secure.

The takeaway is simple: AI is an incredibly useful assistant, but the output still needs to be reviewed, tested, and understood by someone with real technical experience.

At AmbroTech, we believe technology should be built properly and securely, not just quickly. That means real review, real testing, and real accountability behind the systems people rely on.

AmbroTech
IT that works. Support that cares. 🐞💻

Leave the first comment

Browse Our Services

Free Web & IT Health Check

Please give us some contact details and we’ll reach out to you for a free web & IT health check.

Name(Required)