UpGuard researchers analysed a dataset of roughly 300,000 domains that appeared to use Supabase, an open-source platform built around PostgreSQL that provides backend services for rapid app development. The team checked for a 'users' table and found that while some queries returned a page from the database, others indicated that a different table was publicly accessible. By examining table schemas, the researchers inferred what types of data were exposed in more than half the cases.
The findings included a US valet service that leaked more than 100,000 customer records with contact details, licence plates and visit history. A Canadian immigration service exposed nearly 5,000 user records, including 884 plaintext passwords. Sensitive identity and payment account information, along with over 100,000 private messages, were found at an India-based adult creator platform. A Philippines-based OTP service exposed data on more than 2,000 users and 100,000 SMS messages, some containing apparently unrelated person-to-person communications. An African government consulate exposed records belonging to 25,000 people, including addresses and emergency housing locations.
UpGuard attributes the exposure to missing or ineffective row-level security policies and misuse of public keys. The researchers note that AI-assisted development now accounts for more than 60% of newly created Supabase databases, and that many site owners are unaware of their database's configuration. “The security settings are invariant to business type because the humans, who know what kind of business they are advertising, do not understand their database’s configuration,” UpGuard explains. “The common thread is that these sites are created by AI coding agents and the humans are unaware of the configuration.” The firm stressed that its scans do not prove every affected site was built with an AI coding agent.
UpGuard says it notified application owners when deeper analysis identified significant exposure. Supabase users are advised to review the platform's security documentation, including its advisors and guides on securing APIs.