Friday, September 25, 2026
Home / Technology / Some Supabase customers are publicly exposing ream...
Technology

Some Supabase customers are publicly exposing reams of people’s data to the web

CN
CitrixNews Staff
·
Some Supabase customers are publicly exposing reams of people’s data to the web

Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.

UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases.

Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances to the tune of millions of records each.

The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of.

Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans and children’s personal information.

Now, the boom in AI vibe-coding is helping fuel a new wave of data breaches, many of which are now being linked to Supabase as people increasingly use it for storing their data.

UpGuard says it sought to understand the scale of exposed data across the platform, and found publicly accessible names, addresses, phone numbers and user passwords. The research surfaced a fewer number of passwords and authentication tokens.

Originally reported by TechCrunch. Read the full story at the original source.