Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with sensitive data such as PII, passwords, authentication tokens, and in some cases credit card information. UpGuard linked the exposure to weak configuration practices in AI-assisted app development and advised users to review Supabase security controls to reduce risk. #Supabase #UpGuard #AIcodingagents
Keypoints
- More than 16,000 Supabase databases were found misconfigured and exposing data.
- Exposed tables contained PII, passwords, authentication tokens, and some credit card data.
- UpGuard analyzed about 300,000 domains and inferred exposure through table schemas.
- Notable leaks included a U.S. valet service, a Canadian immigration service, and an India-based adult creator platform.
- Researchers blamed poor security settings, missing row-level security, and misuse of public keys.