The AI Post
Agents & CodingOpen ModelsEnterpriseFundraisingGenerative MediaGovernanceInferenceInfrastructureLegal & SafetySector Impact
← Front Page Security · Supabase · UpGuard

UpGuard finds AI‑built apps exposed 16,000 Supabase databases

The security firm says vibe-coded apps left passwords, addresses and phone numbers publicly viewable across thousands of Supabase-hosted projects.

Cybersecurity firm UpGuard said it found about 16,000 Supabase-hosted databases exposing personal data on the open internet. The data included passwords, phone numbers and authentication tokens, and many of the apps behind them were built with AI coding tools, UpGuard said.

UpGuard tied much of the exposure to apps generated with AI tools, often called vibe-coded software. Developers deployed the apps without the security settings Supabase requires to keep a database private, TechCrunch reported. The examples included private messages from an Indian adult streaming platform, license plate records from a US valet company and a contact database for an African government's consulate in France.

Other exposed systems included a virtual SIM farm used to intercept verification texts for fraud, plus client records from an immigration and relocation service, according to the report. Supabase reached a $10 billion valuation in June. Its rapid growth among developers building with AI assistants has made misconfiguration a recurring problem on the platform.

Supabase chief information security officer Bil Harmer said the company is working to make secure defaults easier to reach. "Security at Supabase is never finished," Harmer said. "We care deeply about getting it right, and we'll keep making it easier for every developer to ship securely."

UpGuard did not say how many of the exposed databases have since been secured. It also did not say whether attackers accessed the data before researchers found it. The findings add to a growing list of incidents in which AI-assisted coding tools shipped working software that skipped security steps a human developer might have caught.

Sources 1 source

  1. Source TechCrunch