Some Supabase Customers Are Publicly Exposing Large Amounts of User Data, Research Finds
The findings highlight how AI-generated and vibe-coded apps can leak users' data when not properly configured or secured.
Written by EGazette’s AI. The facts are drawn from cited sources; the analysis is the AI’s own.
Some customers using the Supabase platform are publicly exposing large amounts of user data to the web, according to findings reported by TechCrunch.
The research highlights how applications built using AI-generated code or through so-called vibe-coding practices can end up spilling and exposing users' data when they are not properly configured or secured, pointing to a broader risk tied to the rapid, AI-assisted development of applications.
A risk tied to configuration, not the platform itself
The exposures appear to stem from misconfiguration on the part of individual customers building applications on Supabase, rather than from a flaw in the platform itself, underscoring how easily security settings can be overlooked when apps are built quickly, including with the help of AI coding tools.
As AI-assisted and vibe-coded development has become more common, allowing developers, including those with less technical background, to build and deploy applications rapidly, concerns have grown about whether adequate attention is being paid to security fundamentals such as access controls and data permissions.
The findings serve as a reminder that speed of development does not eliminate the need for careful configuration of backend services, particularly when those services store sensitive user data.
It was not specified in the available reporting how many customers or how much data was affected, or whether Supabase has taken any steps in response to the findings.
Sources
EGazette summarizes reporting from multiple sources; follow the links for the originals.
Related articles

Mark Wahlberg to Join TechCrunch Disrupt 2026, Focused on Founders' Stories
The actor and entrepreneur will speak with Bruce K. Lee at Disrupt about investing, entrepreneurship, healthcare and wellness, and building businesses, according to TechCrunch.
Muju Earth's Aeropod Automates Soil Aeration Without Robotics, Debuting at TechCrunch Disrupt
The simple pod is designed to save farmers money while improving crop yields, without relying on robotic components.
Lithuania's Interior Ministry Reports Cyberattack on Information System
Interior Minister Martynas Katelinas was informed of a cyberattack affecting a system administered by the ministry's IT department.
Meta's Muse AI Chatbot Found to Expose Its Own Filesystem to Users
Users discovered that with some prodding, Muse would reveal internal files it reportedly wasn't supposed to disclose.

FBI hack exposes agents' blood and urine test results
A cyberattack on the FBI resulted in the theft of special agents' blood and urine test results, raising concerns about potential blackmail and targeted attacks.
North Korean Hackers Suspected in $351 Million Crypto Theft, Largest So Far This Year
The theft from crypto exchange Bitget is the latest in a string of high-profile hacks targeting the crypto sector, TechCrunch reports.
Comments
Loading comments…