UpGuard Finds 16,000 Supabase-Hosted Databases Exposing Personal Data
UpGuard says about 16,000 Supabase-hosted databases exposed personal data online, highlighting security risks tied to misconfigured vibe-coded apps.
Thousands of databases hosted on development platform Supabase are exposing personal information to the public internet, according to new research from cybersecurity firm UpGuard.
UpGuard said it identified about 16,000 Supabase-hosted databases where some personal data was publicly accessible. The exposed information included names, addresses and phone numbers, along with a smaller number of passwords and authentication tokens.
The findings highlight a growing security problem as developers increasingly use AI tools to build apps quickly. While AI-assisted development can simplify coding, applications can still expose sensitive information when databases or access controls are configured incorrectly.
Misconfigured databases expose sensitive records
Supabase has grown rapidly alongside the popularity of AI-assisted and vibe-coded apps, but researchers have repeatedly documented cases involving misconfigured Supabase APIs and publicly accessible Supabase instances.
Some incidents have exposed extremely large datasets. Previous security research has documented cases involving millions of records and API credentials.
UpGuard said the databases it discovered covered a wide range of services. They included private conversations involving users of an Indian adult streaming site, thousands of license plates from a U.S. valet service and contact information belonging to customers of an immigration and relocation service.
Researchers also found a database associated with an African government consulate in France and another linked to a virtual SIM farm that intercepted text messages containing one-time passcodes used to verify online accounts.
Although most of the exposed datasets appeared to be located in the United States, UpGuard described the problem as global.
AI-built apps add to an existing security problem
Improperly configured cloud infrastructure has caused data exposures for years, but the rapid growth of AI-generated applications is creating another source of risk. Developers can launch software quickly without always understanding the security settings required for the databases and services behind it.
Earlier research has identified exposed Supabase databases connected to Y Combinator startups, while another study of 1,072 vibe-coded applications reported security flaws across much of its sample.
The issue is not necessarily a vulnerability in Supabase itself. Public exposure can result when customers configure database permissions or APIs in ways that allow unintended access.
Supabase says projects are secure by default
Supabase has introduced security changes and additional database-access protections over time.
Supabase Chief Information Security Officer Bil Harmer said the company had not reviewed UpGuard’s research but maintained that its projects are “secure by default.” He described security as a shared responsibility between Supabase and its customers.
“We provide secure defaults and tooling, and customers control how their own projects are configured,” Harmer said, adding that Supabase notifies affected customers when it discovers security issues.
UpGuard security researcher Greg Pollock said the research was intended to raise awareness of how widespread these exposures can become as more applications rely on platforms such as Supabase for storing user information.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0