Supabase Data Exposure: 16,000 Databases Leak Sensitive Personal

Supabase Data Exposure: 16,000 Databases Leak Sensitive Personal Data Across the Web


Thousands of databases hosted by development platform Supabase are exposing people's sensitive information to the public web, according to new security research from cybersecurity firm UpGuard.


The Scale of the Problem


UpGuard told TechCrunch that it found approximately 16,000 databases on which some degree of personal data was exposed while hosted by Supabase, a platform that allows web and app developers to store and run their databases.


The findings come amid Supabase's rapid rise. Earlier this year, the company doubled its valuation to $10 billion in just eight months, fueled by a surge of developers hosting their vibe-coded apps on the platform. Yet the company has faced persistent criticism over how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet—in some instances, to the tune of millions of records each.


Why Vibe-Coded Apps Are Fueling a New Wave of Breaches


These findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools make it easier than ever to build websites and apps, the generated code often contains security flaws—or the apps require specific configuration that the developer may be entirely unaware of.


Over the years, countless data breaches have been linked to improperly configured storage servers, databases, and websites. Such cases have resulted in the leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver's license scans, and children's personal information.


Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches—many of which are increasingly being linked to Supabase as more people turn to it for data storage.


What Was Found Exposed


UpGuard says it sought to understand the scale of exposed data across the platform and found publicly accessible names, addresses, phone numbers, and user passwords. The research surfaced a smaller number of passwords and authentication tokens.


The firm said the databases contained data linked to a wide range of projects, including:


  • Private conversations with sex workers on an Indian adult streaming site
  • Thousands of license plates from a U.S. valet service
  • Contact information of people who used an immigration and relocation service
  • A database belonging to an African government's consulate in France
  • A virtual SIM farm used to intercept text messages and send one-time passcodes for verifying online accounts—typically for launching scams and phishing attacks

While the majority of these exposed datasets appear to be located in the United States, UpGuard said this is a worldwide problem. The findings build on earlier research that also found a range of exposed databases hosted on Supabase, including those by Y Combinator startups and other popular apps.


Supabase's Response


Supabase has made changes to its platform over the years, including bolstering its platform and user access to databases. However, the scale of the exposure—16,000 databases—suggests that misconfigurations remain a systemic issue for the platform and its users.


For developers building on Supabase, the findings underscore the importance of properly configuring row-level security, API access controls, and database permissions before going live. AI-generated code may accelerate development, but it does not eliminate the need for security review.

via TechCrunch AI

Related