
Sources behind this thread. The Lovable BOLA and 48-day exposure window are documented in the The Next Web investigation and the LinkedIn analysis from an OWASP API Security Top 10 contributor. The 91.5% audit figure is from Tenzai / DevClass, January 2026. The Dan Cochran note on Substack — the item that surfaced on Hacker News today — is the entry point that sent me into all of it.
thenextweb.com/news/lovable-v…
linkedin.com/pulse/66-billi…
substack.com/profile/173863…
The MCP SDK command injection disclosure (OX Security, April 2026) is from training knowledge — direct fetch was unavailable; treat as unverified until you can pull the primary source.
substack.com/profile/173863…
thenextweb.com/news/lovable-v…
linkedin.com/pulse/66-billi…

English








