Find security holes AI tools left behind.
Free instant scan. Finds exposed Supabase service keys, missing RLS, open Firebase rules, leaked secrets in your JS bundle, and more.
- No signup required
- 500+ checks performed
- BaaS-aware
- Auth-safe (passive)
Scanner coverage
- 210+
- vulnerability classes covered
- 270+
- passive checks / scan
- 120+
- active checks / scan
- 150+
- GitHub checks / scan
Compatible with
Scan websites and apps built with AI coding tools.
Deploy from Cursor, Claude Code, Codex, Lovable, Bolt, v0, Replit, and more. FixVibe checks the shipped URL and repo for security gaps AI-generated apps tend to miss.
- Cursor
- Claude Code
- OpenAI Codex
- GitHub Copilot
- Lovable
- Bolt.new
- v0
- Replit Agent
- Windsurf
- Devin
- Google Jules
- Gemini CLI
- Firebase Studio
- Amazon Q Developer
- JetBrains Junie
- Kiro
- Tabnine
- Qodo
- Sourcegraph Amp
- Continue
- Cline
- Roo Code
- Aider
- OpenCode
- Base44
- Anything
- Builder.io Fusion
- Tempo
- Softgen
- Trae
Latest research
New vulnerabilities, every day.
We track newly disclosed CVEs, GHSA advisories, and BaaS misconfiguration patterns that matter to AI-built apps. Public notes explain impact and safe remediation at a high level.
- criticalresearch note
Out-of-Bounds Read in Linux Kernel ksmbd (CVE-2023-3867)
The Linux kernel's ksmbd module is vulnerable to an out-of-bounds (OOB) read during SMB2 session setup. This occurs when a session setup request is part of a compound request, specifically if it is the second payload in the sequence. Attackers can leverage this to cause system crashes or potentially leak sensitive kernel memory.
- criticalresearch note
mcp-server-kubernetes Argument Injection Exposes Cluster Credentials
A critical argument injection vulnerability (CVE-2026-61459) in mcp-server-kubernetes allows attackers to manipulate command-line arguments. This flaw can be exploited to leak sensitive Kubernetes cluster credentials or gain unauthorized access to the cluster environment.
- highresearch note
CVE-2025-68428: Path Traversal in jsPDF Node.js Build
A high-severity vulnerability (CVE-2025-68428) has been identified in the jsPDF library. In Node.js environments, the loadFile method fails to properly sanitize the first argument, allowing attackers to perform path traversal and local file inclusion (LFI). This can lead to unauthorized access to sensitive server-side files if user input is passed directly to the method.
Current research, practical context, and coverage updates when checks ship.
All research →