signalTechCrunch AI2026-09-26
Some Supabase customers are publicly exposing reams of people’s data to the web
UpGuard found around 16,000 Supabase-hosted databases exposing personal data like names, addresses, phone numbers, and passwords. Supabase reached a $10 billion valuation this year, but misconfigurations by customers have led to widespread leaks. The research highlights how vibe-coded apps often have security flaws that expose sensitive information.
- for who
- Developers building and hosting applications on Supabase, especially those using vibe-coding tools
- why now
- New UpGuard research exposes 16,000 vulnerable Supabase databases, a fresh warning for vibe-coders.
- what changes
- They must treat database configuration as a critical security step, not an afterthought, to avoid public exposure of user data
- to do
- Review and tighten Supabase database access controls and authentication settings immediately, following the platform's secure defaults
key points
- UpGuard found 16,000 exposed Supabase databases with personal data
- Supabase is valued at $10 billion, boosted by vibe-coding apps
- Misconfigurations leak data, including passwords and auth tokens
#data security#Supabase#vibe-coding#data leak
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source