The app your team built with AI may be leaking its users table. Check Supabase today

By George Bailey   Published: 09/29/26   4 min read

Somebody in marketing built a sign-up page over a weekend. A contractor shipped a customer portal in two sprints with a coding assistant. A founder launched a waitlist. A lot of those projects sit on Supabase, and a new study says thousands of them are leaving their tables readable by anyone who knows where to look.

The app shipped in a weekend. The row level security never shipped at all.

What happened

UpGuard researchers collected about 300,000 domains that showed signs of using Supabase, the hosted PostgreSQL platform popular with AI coding tools, and asked each database for a users table. They found 16,326 databases exposing readable tables. Based on table schemas, more than half had indicators of personal information, a smaller share appeared to hold passwords or authentication tokens, and a very small number had plausible payment card data. BleepingComputer covered the findings on September 28.

UpGuard checked a handful of cases by hand. They included a U.S. valet service exposing more than 100,000 customer records with phone numbers, license plates, and visit history; a Canadian immigration and relocation service with nearly 5,000 user records, 884 of them with plaintext passwords; an African government consulate with records on 25,000 people, including emergency housing locations; and a Philippines OTP service exposing over 100,000 SMS messages. UpGuard says it notified owners where it found significant exposure.

The cause is configuration, not a Supabase software flaw: missing or ineffective row level security (RLS) policies and public keys used as if they were secret. UpGuard notes Supabase now enables RLS by default for tables created in its Table Editor, but tables created programmatically through the API, which is how coding agents usually work, do not get RLS by default. UpGuard also stresses that its scan does not prove every affected site was built with an AI agent.

Why it matters

Security teams rarely know these projects exist. They start as experiments outside the normal review path, then quietly start collecting real customer data. The exposure also cuts both ways: about 11% of the email addresses in the valet dataset belonged to corporate domains, so your employees’ data can leak from someone else’s side project.

What to do first

Forward this

If you or a contractor built an app or site on Supabase, please open the project’s security advisors today and confirm row level security is on for every table. Researchers found more than 16,000 Supabase databases readable by anyone.

Details

Hunt / verify

Slack paste: Supabase: list every project with real users, run the security advisors, RLS on for every table with real policies, publishable key only in the browser, rotate exposed keys, no plaintext passwords.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.