可爱的应用程序暴露了18,000用户:未曾预见的Vibe编码安全危机

📄 中文摘要

2026年2月27日,安全研究员Taimur Khan在Lovable平台上发现了一款应用程序存在16个安全漏洞,其中6个为关键漏洞。这款应用是一个AI驱动的教育科技工具,旨在生成AI考试和评分学生提交的作业。漏洞导致加州大学伯克利分校、加州大学戴维斯分校及K-12学校的学生数据泄露,影响了约18,000名用户。此事件揭示了在AI应用开发中,安全性的重要性和潜在风险,提醒开发者在构建AI工具时必须重视安全防护措施。

📄 English Summary

Lovable App Exposes 18,000 Users: The Vibe Coding Security Crisis Nobody Saw Coming

On February 27, 2026, security researcher Taimur Khan discovered 16 vulnerabilities, including 6 critical ones, in a single app hosted on Lovable's platform. This AI-powered EdTech tool, designed to generate AI exams and grade student submissions, leaked data from students at UC Berkeley, UC Davis, and K-12 schools, affecting approximately 18,000 users. The incident highlights the importance of security in AI application development and the potential risks involved, urging developers to prioritize security measures when building AI tools.

Powered by Cloudflare Workers + Payload CMS + Claude 3.5

数据源: OpenAI, Google AI, DeepMind, AWS ML Blog, HuggingFace 等