Cybersecurity firm UpGuard reported that approximately 16,000 databases hosted on the Supabase development platform were publicly accessible, exposing personal information to the open web. The investigation, disclosed to TechCrunch, found varying degrees of data leakage across these instances, indicating a widespread issue rather than isolated missteps.
Supabase enables web and app developers to store and operate databases, and earlier this year achieved a valuation of $10 billion as developers increasingly deployed “vibe-coded” applications on its service. Despite rapid growth, the company has faced criticism over its security posture, with numerous reports of users inadvertently exposing databases that contain millions of records.
The surge in AI-generated code, often referred to as vibe-coding, has lowered barriers for building websites but frequently introduces security flaws. Improper configuration of storage servers, databases, or web servers has historically led to breaches involving military emails, immigration applications, classified files, driver’s license scans and children’s personal data. Supabase’s popularity now links it to a new wave of such exposures.
UpGuard’s analysis uncovered publicly reachable records such as names, addresses, phone numbers and user passwords, though fewer authentication tokens were observed. Specific datasets included private conversations from an Indian adult-streaming platform, thousands of license-plate numbers belonging to a U.S. valet service, contact details of users of an immigration and relocation provider, a database linked to an African government consulate in France, and a virtual SIM farm used to intercept one-time passcodes for phishing campaigns.
Supabase’s Chief Information Security Officer Bil Harmer responded that the firm had not seen the UpGuard report but maintains that its projects are “secure by default.” He emphasized a shared-responsibility model, noting that Supabase provides secure defaults and tooling while customers configure their own projects, and that the company notifies affected users when security issues are identified.
UpGuard researcher Greg Pollock described the findings as a valuable effort to raise awareness of data exposures on developer platforms. He highlighted the need for continuous improvement in security practices, especially as AI-driven development accelerates, and urged both providers and developers to adopt stronger safeguards to protect sensitive information.