Over 16,000 misconfigured Supabase databases expose PII, passwords and auth tokens

Cybersecurity firm UpGuard finds systemic data exposure in apps built on the open-source backend platform, with AI-assisted development linked to many cases

edit
By LineZotpaper
Published
Read Time2 min
More than 16,000 Supabase databases have been found exposing readable tables containing personally identifiable information, plaintext passwords and authentication tokens, according to a study by cyber risk management firm UpGuard. A small subset of the exposed data is believed to include credit card information.

UpGuard researchers analysed a dataset of roughly 300,000 domains that appeared to use Supabase, an open-source platform built around PostgreSQL that provides backend services for rapid app development. The team checked for a 'users' table and found that while some queries returned a page from the database, others indicated that a different table was publicly accessible. By examining table schemas, the researchers inferred what types of data were exposed in more than half the cases.

The findings included a US valet service that leaked more than 100,000 customer records with contact details, licence plates and visit history. A Canadian immigration service exposed nearly 5,000 user records, including 884 plaintext passwords. Sensitive identity and payment account information, along with over 100,000 private messages, were found at an India-based adult creator platform. A Philippines-based OTP service exposed data on more than 2,000 users and 100,000 SMS messages, some containing apparently unrelated person-to-person communications. An African government consulate exposed records belonging to 25,000 people, including addresses and emergency housing locations.

UpGuard attributes the exposure to missing or ineffective row-level security policies and misuse of public keys. The researchers note that AI-assisted development now accounts for more than 60% of newly created Supabase databases, and that many site owners are unaware of their database's configuration. “The security settings are invariant to business type because the humans, who know what kind of business they are advertising, do not understand their database’s configuration,” UpGuard explains. “The common thread is that these sites are created by AI coding agents and the humans are unaware of the configuration.” The firm stressed that its scans do not prove every affected site was built with an AI coding agent.

UpGuard says it notified application owners when deeper analysis identified significant exposure. Supabase users are advised to review the platform's security documentation, including its advisors and guides on securing APIs.

§

Analysis

Why This Matters

  • Developers using Supabase may inadvertently expose user data if they fail to configure row-level security (RLS) policies correctly, especially when relying on AI coding agents that generate code quickly without built-in security checks.
  • The leaked information — including plaintext passwords, authentication tokens and private messages — puts millions of users at risk of identity theft, account takeover and fraud.
  • The findings underscore a broader industry challenge: rapid, AI-assisted development can outpace developers' understanding of the security configurations of the platforms they use.

Background

Supabase is an open-source alternative to Firebase that has grown rapidly among startups and individual developers. It provides authentication, storage and real-time database features out of the box, but its security model depends on PostgreSQL's Row-Level Security (RLS). If RLS is not enabled or is misconfigured, tables can be publicly readable by anyone who knows the database URL. The platform has published detailed documentation and an "advisors" feature to help prevent such issues, but the UpGuard study suggests many users are not applying these settings correctly.

Key Perspectives

Developers and startups using Supabase: They face an urgent need to audit their Supabase projects, enable RLS on all tables, and ensure API keys are used correctly. Many may be unaware that their data is publicly accessible, and those who relied on AI-assisted code generation may have skipped security steps. End users and customers: Their personal data, including contact details, passwords and private messages, may have been exposed without their knowledge. They should monitor for identity theft or phishing attempts and consider contacting the affected services. Security researchers and UpGuard: The firm identified the scale of exposure and responsibly notified affected owners. It highlights that misconfigurations are not limited to any particular industry and that human error — amplified by AI coding tools — is the common thread.

What to Watch

  • Whether any of the named organizations (the US valet service, Canadian immigration service, India adult platform, Philippines OTP service, African consulate) confirm the exposure and notify affected users.
  • Supabase's response: the company may release new warnings, defaults or automated checks to prevent RLS misconfigurations in newly created projects.
  • Potential regulatory action in jurisdictions with strict data protection laws, such as GDPR in Europe or the Privacy Act in Australia, if the exposed data involves residents of those regions.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.