Supabase customers expose ~16,000 databases to public web

Original: Some Supabase customers are publicly exposing reams of people’s data to the web

Why This Matters

The vibe-coding boom is generating apps at scale with misconfigured backends, creating a new, largely ungoverned class of data exposure.

Cybersecurity firm UpGuard found roughly 16,000 Supabase-hosted databases exposing personal data publicly — names, addresses, phone numbers, passwords, and auth tokens — spanning an Indian adult platform, a U.S. valet service, an immigration firm, and an African government consulate in France.

UpGuard researchers scanned Supabase-hosted databases and identified around 16,000 instances where some degree of personal data was publicly accessible without authentication. Exposed records included names, addresses, phone numbers, and in fewer cases, plaintext passwords and authentication tokens. Among the affected databases: private messages from users of an Indian adult streaming platform, thousands of license plates from a U.S. valet service, contact data from an immigration and relocation service, files tied to an African government consulate in France, and a virtual SIM farm apparently used to intercept one-time passcodes — a classic setup for fraud and phishing. UpGuard says the problem is global, despite the majority of exposed data appearing U.S.-based. The findings follow earlier research that flagged similar misconfigurations at Y Combinator-backed startups and other widely-used apps. Supabase, which hit a $10 billion valuation earlier this year on the back of surging demand from "vibe-coded" app developers, has faced repeated criticism over its security posture. The root issue is largely misconfiguration — not a platform breach — but the scale points to a structural gap: AI-assisted development makes it easy to ship apps fast while skipping security basics.

Source

techcrunch.com — Read original →