Original caption
Can someone steal your users' data just by pasting a URL? If your app doesn't check who's asking for that data, then yes. In this one I break down one of the most common vulnerabilities we find at Casco: Insecure Direct Object Reference, or IDOR. Change a single ID in a URL, and a broken app will hand over someone else's private data. If you're vibe coding an app right now, watch this before you ship it. #cybersecurity #vibecoding #softwareengineering #startup