NoCodeBackend

Product details
miyanmiyan
miyanPLUS
Edited Sep 25, 2026

Q: Until Sept 25, a user's email alone let others see their databases and secret keys. Will you warn and investigate?

Until Sept 25, a serious bug let any registered user — free or paid — open any other user's account with just that user's email address. They could see every database that person built and its secret key: full control to read, change, or delete everything inside.

I reported it privately with steps to reproduce; it is now fixed.

But a quiet fix is not enough. My questions:

1. Will you tell all users honestly that this bug existed, and warn them not to store private data until they change their keys?

2. Will you admit these risks were real, and advise everyone to change their keys and check their data for changes they didn't make?

3. We can't know if this bug was used — it left no trace for victims. Will you check your records for that period and share the results?

A quiet fix protects code, not people. What will you tell them?

Share
Helpful?
3
Log in to join the conversation

Verified purchaser

Thank you for those questions.