Some Supabase customers are publicly exposing reams of people's data to the web

The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.

Some Supabase customers are publicly exposing reams of people's data to the web

TL;DR

  • Cybersecurity firm UpGuard discovered around 16,000 Supabase databases publicly exposing sensitive personal data.
  • Exposed information includes names, addresses, phone numbers, user passwords, and authentication tokens.
  • The findings highlight security risks associated with AI-generated code and improper database configurations.
  • Examples of exposed data range from private conversations on an adult streaming site to license plates and immigration service contacts.
  • Supabase states that security is a shared responsibility, with the company providing secure defaults and customers managing configurations.