Follow the latest coverage, related explainers and connected technology stories.
Researchers at UpGuard found that more than 16,000 databases associated with Supabase allowed access to readable tables, containing personal data in more than half of cases, with passwords and authentication tokens present in a smaller group. The flaw is linked to incorrect security settings, including row-level security policies and improperly used public keys.
UpGuard found that nearly 16,000 databases hosted on Supabase made some personal data accessible online, including names, addresses, phone numbers, passwords, and authentication tokens. The findings highlight the risks of applications built with artificial intelligence tools when access settings and databases are left inadequately secured.