Supabase Data Exposure: Customer Errors Expose Public Records

▼ Summary
– Cybersecurity firm UpGuard discovered that approximately 16,000 databases hosted on the Supabase platform were exposing sensitive personal data to the public web.
– The exposed information included names, addresses, phone numbers, passwords, and specific datasets such as license plates and private conversations from various global services.
– This security issue highlights broader risks associated with AI vibe-coding tools, which often generate code containing security flaws or require complex configurations that developers may misunderstand.
– Supabase, a rapidly growing development platform valued at $10 billion, has faced increasing criticism for user misconfigurations leading to significant data breaches over time.
– While the majority of affected datasets originated in the United States, UpGuard emphasizes that this is a worldwide problem stemming from improper security practices across the platform.
Thousands of Supabase databases are inadvertently exposing sensitive personal information, according to new security research conducted by cybersecurity firm UpGuard. The investigation identified approximately 16,000 databases hosted on the platform where some degree of personal data was accessible to the public web. Supabase, a popular development tool that allows web and app creators to store and run their databases, has seen its valuation soar to $10 billion earlier this year as more developers migrate their “vibe-coded” applications to its infrastructure.
Despite this rapid growth, the company has faced increasing scrutiny over its approach to user security. There are numerous documented instances where users misconfigured their systems or unknowingly left their databases open to the broader internet, resulting in the exposure of millions of records in single incidents. These findings underscore a growing concern regarding how AI-generated code and hastily built websites can spill sensitive data through basic configuration errors. While artificial intelligence tools simplify the creation of digital products, the resulting code often contains inherent security flaws, or requires specific settings that inexperienced developers may not understand.
A History of Misconfiguration Breaches
Data breaches linked to improperly configured storage servers, databases, and websites have been a persistent issue for years. Such vulnerabilities have previously led to the leak of sensitive military communications, immigration and visa applications, classified government documents, hundreds of thousands of driver’s license scans, and personal information belonging to children. The current surge in AI-driven vibe-coding is fueling a new wave of these breaches, with many recent incidents now tied directly to Supabase as it becomes the preferred backend for storing application data.
UpGuard’s research aimed to quantify the scale of exposed data across the platform. The study revealed publicly accessible names, addresses, phone numbers, and user passwords, along with a smaller number of authentication tokens. The exposed databases contained highly sensitive information from diverse projects. These included private conversations involving sex workers on an Indian adult streaming site, thousands of license plates from a U. S. valet service, and contact details for individuals using an immigration and relocation service. Additionally, one database belonged to an African government’s consulate in France, while another was utilized by a virtual SIM farm to intercept text messages containing one-time passcodes, typically for launching scams and phishing attacks.
Shared Responsibility and Platform Security
Although the majority of these exposed datasets appear to be located in the United States, UpGuard emphasized that this is a global issue. The findings expand upon earlier research that also identified a range of exposed databases on Supabase, including those belonging to Y Combinator startups and other well-known applications. In response to ongoing concerns, Supabase has implemented changes to its platform over the years, aiming to bolster security measures and improve user access controls for databases.
When contacted for comment, Supabase’s Chief Information Security Officer Bil Harmer stated that the company had not yet reviewed the specific research but maintained that its projects are “secure by default.” He characterized security as a shared obligation between the provider and its users. “We provide secure defaults and tooling, and customers control how their own projects are configured,” Harmer explained, noting that the company notifies affected customers when security issues are discovered.
Harmer further emphasized the company’s commitment to continuous improvement in safety protocols. “Security at Supabase is never finished. We care deeply about getting it right, and we’ll keep making it easier for every developer to ship securely,” he said. UpGuard security researcher Greg Pollock noted that the firm’s research was crucial for raising awareness about the pervasive problem of data exposures in modern development environments.
(Source: TechCrunch)




