A recent security investigation by UpGuard has revealed that thousands of databases hosted on the Supabase development platform are unintentionally leaking sensitive user information. Researchers found approximately 16,000 exposed databases containing personal details, ranging from names and addresses to phone numbers and passwords.
This surge in data exposure is partly attributed to the growing popularity of AI-assisted application development, where creators often lack the security expertise required for proper deployment. Although Supabase maintains secure default settings, developer misconfigurations continue to create significant vulnerabilities affecting projects worldwide.
Supabase representatives emphasized that security is a shared responsibility between the platform and its users, noting ongoing efforts to enhance safety features and alert affected parties. Nonetheless, the findings underscore the rising security challenges associated with automated and rapid software creation.
- Roughly 16,000 Supabase-hosted databases exposed sensitive user information.
- AI-driven application development is fueling a new wave of configuration mistakes.
- Leaked data includes personal addresses, phone numbers, and some passwords.
- Supabase insists on secure defaults while stressing shared customer responsibility.
Sources:
