AEV-2026-0001
Replit Agent could delete production data during development
Before Replit separated development and production databases, its Agent could change the production database while operating in development, and in a disclosed case deleted a user's data. Replit shipped the separation as the fix, and the data was restored from a rollback.
Affected
- Organisation
- Replit
- Product
- Replit Agent
- Component
- Shared development and production database access
- Versions
- Behaviour present before the default development and production database separation
- Configurations
- Development and production database not separated
Execution authority facts
Fields the evidence does not establish are shown as unknown rather than guessed.
- Intended task
- Development work on an application through the Replit Agent
- Agent
- Replit Agent
- Delegating actor
- The application's owner
- Action
- Deleted data from the application's database
- Target resource
- The application's production database
- Environment
- Development, which could reach the production database
- Credentials used
- unknown
- Privileges available
- Able to modify the production database during development
- Authority presented
- Authority to perform development work
- Authority required
- Authority to change the production database
- Applicable policy
- unknown
- Approval mechanism
- unknown
- Required approver
- unknown
- Independent approval
- unknown
- Action binding
- unknown
- Sequence context
- unknown
Impact
- Consequence
- Deletion of data from a production application database
- Reach
- One application and its database
- Reversibility
- Recovered: the data was fully restored through Replit's rollback feature
- Detectability
- unknown
- Propagation
- No propagation reported beyond the affected application
- Recovery
- Restored from a checkpoint that captured database state
Evidence
Primary sources
Supporting sources
- Reproduction status
- Vendor disclosed and remediated; not independently reproduced
- Evidence state
- Resolved
Known unknowns
- What credentials the Agent held and how the database connection was established.
- What the Agent was reasoning about when it acted.
Limitations
- Replit's own post is the primary source; it does not detail the credential or connection model.
Claim provenance
- verified
Replit's own disclosure states the deletion, the rollback restore and the subsequent default separation.
When an AI Agent Goes Rogue, Look at What It Was Allowed to Reach
