Skip to content
Trending storyPast story

Some Supabase customers are exposing reams of people’s data to the public web

1 report1 sourceupdated 4 days ago

What happened

Summary

安全公司 UpGuard 发现大概有 1.6 万个托管在 Supabase 上的数据库没做好访问控制,直接对外网敞开。泄露的数据包括密码、医疗记录和身份证件。UpGuard 把锅甩给了 AI 写的代码和“氛围编程”(vibe coding),说开发者图省事跳过了安全设置,导致行级安全(Row-Level Security,就是给不同用户划数据边界的开关...

Coverage

Follow the reports to see the story from different sides.

Sep 26
  1. TechCrunch · AIPick
    Some Supabase customers are exposing reams of people’s data to the public web

    Security firm UpGuard found roughly 16,000 Supabase-hosted databases exposed to the public web without proper access controls. Leaked data includes passwords, medical records, and identity documents. UpGuard points to AI-generated code and vibe coding as factors that let developers skip security steps, leaving Row-Level Security disabled. Supabase says the platform is secure by default and the issue stems from customers turning off RLS or exposing API keys. This looks more like developer security hygiene lagging behind AI speed, not a platform vulnerability.