Unsecured Low-Code Apps Creating Shadow IT Risks, Exposing Sensitive Data
The rapid adoption of low-code/no-code platforms like Replit, Lovable, and Vercel is enabling non-technical users to build and deploy applications without security oversight, creating a growing shadow IT problem. A recent incident highlighted the risk when a customer intake form built on Lovable was deployed directly to a live production database with no authentication or access controls, going undetected until an external audit. Two similar cases were later found, including a survey tool connected to an unencrypted shared repository and a landing page with an exposed API key in client-side code. A 2023 study found 380,000 publicly accessible apps on such platforms, with 22% containing exposed credentials or sensitive data. Experts recommend that organizations deploy external attack surface management tools, enforce security-by-design principles in low-code workflows, and provide mandatory security training for non-technical staff.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in