Lovable Cloud Database Exposure: Security Check and RLS FixLovable Cloud Database Exposure: Security Check and RLS Fix
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
Update on my entry: before publishing, Lovable's security scan warned that my app's database rules let anyone read the customer tables. I checked it myself, and it was true: with the app's public key, all 5 tables returned data. It's the same kind of problem as CVE-2025-48757.The fix: every read and write now goes through server functions, and the public key has no access. The same check now gets "permission denied" on all 5 tables.If you built on Lovable Cloud, you can check yours in two minutes. Open Cloud → SQL editor and run:select tablename, policyname, roles from pg_policies where schemaname = 'public' and (qual = 'true' or with_check = 'true');Any row is a rule that says "true". If its roles include anon or public, anyone with your app's public key can use it.Then check for tables with row level security off:select relname from pg_class c join pg_namespace n on n.oid = c.relnamespace where n.nspname = 'public' and c.relkind = 'r' and not c.relrowsecurity;Both came back empty for my app after the fix. Happy to help if yours doesn't.
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started