« Volver al listado

CVE-2025-48757

Estado: AplazadaCrítica (9.3)—

An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de acceso remoto sin autenticación (AV:N, PR:N, UI:N) a base de datos con permisos insuficientes (CWE-863); permite lectura (C:H) y escritura (I:L) de datos arbitrarios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-48757",
  "cveTags": [
    {
      "tags": [
        "disputed",
        "exclusively-hosted-service"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-48757",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-25T14:55:20.841902Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@mitre.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.3,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "Lovable",
          "product": "Lovable",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2025-04-15"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-05-30T03:15:20.893",
  "references": [
    {
      "url": "https://docs.lovable.dev/changelog",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/lhchavez/625ee42a6c408a850d35e50f8e649de9",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://mattpalmer.io/posts/CVE-2025-48757/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://mattpalmer.io/posts/statement-on-CVE-2025-48757/",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://x.com/danialasaria/status/1911862269996118272",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/lhchavez/625ee42a6c408a850d35e50f8e649de9",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@mitre.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers to read or write to arbitrary database tables of generated sites. NOTE: this is disputed by the Supplier because each individual customer of the Lovable platform accepts a responsibility over protecting the data of their application."
    },
    {
      "lang": "es",
      "value": "Una política de seguridad a nivel de fila de base de datos insuficiente en Lovable hasta el 15 de abril de 2025 permite que atacantes remotos no autenticados lean o escriban en tablas de bases de datos arbitrarias de sitios generados."
    }
  ],
  "lastModified": "2026-06-17T09:30:17.293",
  "sourceIdentifier": "cve@mitre.org"
}