publicly readable Supabase databases. UpGuard analyzed approximately 300,000 domains using Supabase, finding that in 16,326 databases some tables were accessible for reading. Analysis of these table schemas revealed signs of personal data in over half the cases, including passwords and authentication tokens.

Researchers identified 16,326 Supabase databases with readable tables in a sample of approximately 300,000 domains showing signs of platform usage. The research focused on identifying the ‘users’ table, analyzing the data types present in the schemas of accessible tables.
publicly readable Supabase databases: why it matters
Few cases contained plausible credit card data, but more frequently, schemas indicated payment system integration. This is not sensitive data itself but signals potential access points for financial attacks. The main causes were identified as the absence or ineffectiveness of row-level security (RLS) policies—the mechanism that controls who can read rows in a table—and the improper use of public keys.
UpGuard links this phenomenon to the growing use of coding agents. Supabase is indeed cited as the most recommended database by Claude Code, and its popularity in this area multiplies potentially vulnerable instances. “Security settings are the same regardless of the type of activity,” explains UpGuard, “because developers, even knowing what kind of service they are advertising, often do not fully understand their database configuration.” However, UpGuard clarifies that the analysis does not prove every involved site was created with a coding agent.
Misconfigured Supabase databases have been reported since 2025. In March of that year, developer Matt Turner highlighted misconfigured databases in applications created with the vibe coding platform Lovable (CVE-2025-48757), while in February 2026 Wiz discovered that the database behind Moltbook, a social network for AI agents, left 35,000 email addresses and 1.5 million API authentication tokens readable.
Supabase, an open-source platform based on PostgreSQL, reached a valuation of $10 billion in June 2026. Previous investigations focused on reduced samples or single vibe coding platforms. Modern Pentest examined 107 Y Combinator startups, finding exposed personal data in 28% of cases; Symbiotic Security analyzed 1,072 apps built with vibe coding, identifying 39 with tables readable via Supabase’s public key; and Escape identified 175 databases containing personal data across approximately 1,400 applications.
UpGuard expanded the investigation to include sites created with Claude Code and OpenAI’s Codex, seeking autonomous domains hosting real activities with real customers. Identification of Supabase sites occurs through key names and database addresses present in public JavaScript files, but large-scale verification requires significant resources. For this reason, UpGuard utilized data collected by BuiltWith, which identifies technologies used by websites, and the Chrome UX Report on BigQuery, to extract raw JavaScript files for keys and addresses.
Approximately 300,000 unique domains emerged, to which the ‘users’ table was requested, chosen because it is present in almost all applications. The database responds in one of three ways: no data accessible due to security policies or database inactivity; a page with query results; or an indication that the ‘users’ table does not exist, suggesting the name of another accessible table.
With over 16,000 databases identified, content analysis was based on table schemas rather than reading every single row. The sectors at highest risk are e-commerce and food service, which frequently expose personal data and integrate payment systems. Unlicensed online betting tends to leave more passwords and credentials readable, while high risk was also found for companies selling industrial goods to business clients.
The type of offering (B2B or B2C) does not affect the categories of exposed data, but geographic distribution shows greater security in Europe, thanks to data protection laws, and more vulnerability in developing regions. The research, focused on the ‘users’ table, naturally led to a higher incidence regarding personal data.
What Changes and What Are the Effects
UpGuard verified the presence of real data by examining some tables with metadata suggesting significant exposures and, if positive, alerted application owners. Among confirmed cases is an Indian site similar to OnlyFans, containing information on 65,467 users (name, email, date of birth, address, driver’s license, passport, PAN card number, and last four digits of Aadhaar), along with payment account details (PayPal, Payoneer, Zelle, crypto wallets, bank) and Stripe account information. A second table, ‘messages’, contains over 100,000 private messages between adult content creators.
A Philippines-based OTP service exposes data on over 2,000 users (emails, phone numbers, and wallet balances) and over 100,000 SMS, some of which appear to be private communications between people not linked to the service. UpGuard had already described the cybercrime supply chain, in which SIM farms represent an important link: many SIMs are used to register fake accounts and increase the number of users involved in scams and illegal activities on Telegram and other social networks.
Other verified cases include a US valet parking service exposing over 100,000 customer records (contacts, license plates, and visit history), a Canadian immigration service with nearly 5,000 user records and 884 plaintext passwords, and an African government consulate with data on 25,000 people (addresses and emergency shelter locations).
Supabase has made RLS active by default on tables created via the Table Editor interface. However, tables created programmatically via API—the channel used by coding agents—do not automatically activate this feature. Even with RLS active, protection depends on correctly configured policies and credentials.
UpGuard believes similar cases will continue to occur, given that typical vibe coding users have little software engineering experience and interact more with the coding agent than directly with code. Those using Supabase can verify their exposure by consulting the platform’s security documentation, particularly guides for advisors and API security.
Source and further reading on publicly readable Supabase databases: original article.
* Content created with the assistance of artificial intelligence systems.
Hardware Ready Ready to Bench?