Latest
Security Firm Finds 16,000 Exposed Supabase Databases Tied to Vibe-Coded Apps
Cybersecurity firm UpGuard found approximately 16,000 Supabase-hosted databases publicly exposing personal data — names, addresses, phone numbers, and some passwords — often due to misconfiguration in AI-generated ('vibe-coded') apps. Supabase says security is a shared responsibility; the exposures show how fast, AI-assisted app building can outpace basic access-control hygiene.
What changes for operators — If your team has used AI coding assistants or no-code/low-code tools to quickly stand up a customer database, internal dashboard, or lead-capture app on Supabase or a similar backend, this is a direct prompt to audit access rules now, not after a breach. Vibe-coded apps are often shipped by non-security-specialists who accept default settings, and the defaults are not always safe — UpGuard's findings show real production data (contact info, tokens, even intercepted verification codes) sitting open to the public internet. For a 10-200 person company, the fix is cheap relative to the exposure: a scheduled review of row-level security and public API access on every database backing a customer-facing or vibe-coded tool, treated as a standing item, not a one-time launch check.