Thousands of databases hosted by Supabase are exposed to the public web, exposing millions of records of sensitive information. UpGuard's research reveals a widespread problem, with databases containing personal data from various projects, including private conversations and government information.
While Supabase claims its projects are secure by default, the reality is that many developers are still misconfiguring their databases, leading to serious data breaches. This issue highlights the growing risk of data exposure in the age of AI-generated code.
The boom in AI vibe-coding is exacerbating the problem, with more and more developers relying on templates and pre-built solutions that may not be thoroughly vetted for security. The consequences can be severe, as evidenced by the range of sensitive data that has been compromised.
Supabase acknowledges its responsibility and has made changes to its platform to improve security, but the challenge remains to educate developers about proper security practices. Until then, the risk of data breaches will continue to grow.







