Skip to content
TechCrunch · AI

Some Supabase customers are exposing reams of people’s data to the public web

Some Supabase customers are publicly exposing reams of people’s data to the web

Security firm UpGuard found roughly 16,000 Supabase-hosted databases exposed to the public web without proper access controls. Leaked data includes passwords, medical records, and identity documents. UpGuard points to AI-generated code and vibe coding as factors that let developers skip security steps, leaving Row-Level Security disabled. Supabase says the platform is secure by default and the issue stems from customers turning off RLS or exposing API keys. This looks more like developer security hygiene lagging behind AI speed, not a platform vulnerability.

Why it matters: UpGuard found ~16,000 Supabase databases publicly exposed due to disabled Row-Level Security, leaking passwords and IDs, and attributed the cause to AI-assisted coding skipping security config. The story has concrete numbers, a clear technical attribution, and ties directly in...

Read the original ↗Export Markdown