Researchers discovered more than 16,000 Supabase databases containing exposed personal information, passwords, authentication tokens, and credit card data. The analysis scanned approximately 300,000 domains showing signs of Supabase platform usage and traced the problem to inadequate security configurations and misuse of public keys.
The exposure highlights a critical security gap in how developers are configuring their database access. When public keys are mishandled or security settings are left in their default state, sensitive customer data becomes accessible to anyone who knows where to look. This isn't necessarily a flaw in Supabase itself—it's a deployment and configuration issue on the developer side.
While AI-assisted development is used in creating over 60% of new Supabase databases, researchers emphasized that their scan does not prove AI-generated code is causing these exposures. The vulnerabilities appear linked to broader practices around credential management and access control rather than a specific tool or approach. Developers using Supabase should audit their security settings, rotate exposed credentials, and ensure public keys are never committed to version control or left in accessible locations.