Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Supabase

Supabase Vendor Cyber Rating & Cyber Score

supabase.com

Build in a weekend. Scale to millions. Supabase is the Postgres development platform. Start your project with a Postgres Database, Authentication, instant APIs, and realtime subscriptions.


Supabase A.I CyberSecurity Scoring

Supabase
Company Information
Website:https://supabase.com
Employees number:454
Number of followers:118,008
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:supabase.com
Supabase Risk Score (AI oriented)
Between 650 and 699
logo
SupabaseIT Services and IT Consulting
Updated:
26/09/2026
668/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Supabase Global Score (TPRM)
xxxx
logo
SupabaseIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SupabaseWeak
Current Score
668B (WEAK)
01000
3 incidents
-30.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
669Before Incident
SEPTEMBER 2026
750Before Incident
Breach
25 Sep 2026 • Supabase
Supabase, Lovable, Replit, Bolt, Indian adult streaming site, U.S. valet parking service and Virtual SIM farm: UpGuard found 16000 Supabase databases leaking user data to the open web

16,000 Supabase Databases Exposed in Mass Misconfiguration Incident

668After Incident
CRITICAL-82
INDSUPUP3REPAMETHULOV1790418715
16,000 Supabase Databases Exposed in Mass Misconfiguration Incident Cybersecurity firm UpGuard uncovered 16,000 publicly exposed Supabase databases leaking sensitive data, including names, passwords, and authentication tokens, according to a TechCrunch report on September 25. The exposed datasets stemmed from misconfigured Postgres row-level security (RLS), a feature designed to restrict database access but left disabled by default in many AI-generated applications. Supabase, a backend platform widely used by AI coding tools like Lovable, Bolt, and Replit, hosts databases for thousands of apps. However, developers often bypass the platform’s dashboard where RLS is enabled by default when using AI-assisted tools that generate SQL migrations directly. This oversight left databases vulnerable, with no authentication required to access them. Among the exposed data were private conversations from an Indian adult streaming site, U.S. valet parking license plate records, immigration firm client details, an African consulate’s database, and infrastructure linked to a virtual SIM farm used in account verification scams. In one case, a Lovable-built education platform exposed 18,000 users, including 14,928 email addresses and 870 full personal records, due to a critical RLS failure (CVE-2025-48757, CVSS 8.26). Supabase’s CISO, Bil Harmer, acknowledged the issue, stating that while the platform provides secure defaults, security remains a shared responsibility with developers. The incident highlights a broader risk: as AI tools automate app development, overlooked security settings like RLS can lead to large-scale exposures when platforms become the default backend for thousands of applications. Supabase, valued at $10.5 billion after a $500 million funding round in June 2026, serves as a critical infrastructure layer for AI-driven development. The scale of this misconfiguration underscores how default settings in high-adoption platforms can amplify security risks when developers rely on automated workflows.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Sensitive data including names, passwords, authentication tokens, private conversations, license plate records, immigration client details, and personal recordsSystems Affected: 16,000 Supabase databasesBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
NamesPasswordsAuthentication tokensPrivate conversationsLicense plate recordsClient detailsPersonal recordsNumber Of Records Exposed: 18,000 users (14,928 email addresses and 870 full personal records in one case)Sensitivity Of Data: HighPersonally Identifiable Information: Yes
AUGUST 2026
747Before Incident
JULY 2026
747Before Incident
JUNE 2026
746Before Incident
MAY 2026
746Before Incident
APRIL 2026
745Before Incident
MARCH 2026
745Before Incident
FEBRUARY 2026
751Before Incident
Vulnerability
26 Feb 2026 • Supabase
Supabase and Lovable: AI-built app on Lovable exposed 18K users, researcher claims

Lovable Platform Under Fire After AI-Generated App Exposes 18,000 Users’ Data

744After Incident
CRITICAL-7
MUSSUP1772216763
Lovable Platform Under Fire After AI-Generated App Exposes 18,000 Users’ Data A security researcher has uncovered critical vulnerabilities in an app hosted on the AI-driven vibe-coding platform Lovable, exposing the personal data of over 18,000 users, including students and educators from top U.S. universities. Tech entrepreneur Taimur Khan identified 16 flaws six deemed critical in an unnamed app featured on Lovable’s Discover page, which had amassed over 100,000 views and 400 upvotes. The app, designed for creating exam questions and managing grades, relied on Supabase for authentication and database management. However, due to missing security controls like row-level security (RLS) and role-based access, the AI-generated backend contained logic flaws that inverted access permissions. For example, a malformed authentication function blocked legitimate users while allowing unauthenticated attackers to access sensitive data, delete accounts, alter grades, and extract admin emails. The exposed dataset included 14,928 unique email addresses, 4,538 student accounts, and 870 records with full personally identifiable information (PII). Users spanned K-12 institutions and universities such as UC Berkeley and UC Davis. Khan criticized Lovable’s response after his initial report was allegedly closed without action, arguing that the platform should bear responsibility for apps it generates and promotes. Lovable’s CISO, Igor Andriushchenko, countered that the company received a "proper disclosure" only on February 26 and acted within minutes, noting that users are responsible for implementing security recommendations from pre-publish scans. He added that the vulnerable database was not hosted by Lovable and that the app’s creator is now addressing the issues. The incident highlights broader concerns about AI-generated code, with studies like Veracode’s finding that 45% of such code contains security flaws. While vibe coding named Collins Dictionary’s Word of the Year for 2025 aims to democratize app development, critics warn that unchecked AI tools can produce functional but dangerously insecure software. Lovable has since contacted the app’s owner to mitigate the risks.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 18,000+ users' data exposedSystems Affected: AI-generated app backend (Supabase)Operational Impact: Unauthorized access to grades, account deletions, and admin email extractionBrand Reputation Impact: Criticism of Lovable’s response and responsibility for AI-generated appsIdentity Theft Risk: High (PII exposed)
DATA BREACH
Email addressesStudent accountsFull PIINumber Of Records Exposed: 18,000+ (14,928 unique emails, 4,538 student accounts, 870 full PII records)Sensitivity Of Data: High (PII, educational records)Data Exfiltration: Possible (unauthenticated access allowed data extraction)Personally Identifiable Information: Yes (full PII in 870 records)
FEBRUARY 2026
754Before Incident
Vulnerability
02 Feb 2026 • Supabase
Supabase and Moltbook: Hacking Moltbook: AI Social Network Reveals 1.5M API Keys

Moltbook: AI Social Network Exposed 1.5M API Tokens in Major Security Flaw

751After Incident
CRITICAL-3
SUPPRO1770195532
Moltbook: AI Social Network Exposed 1.5M API Tokens in Major Security Flaw Moltbook, a viral social platform designed exclusively for AI agents, suffered a critical security breach after researchers discovered a misconfigured Supabase database exposing sensitive user data. The incident, disclosed in late January 2026, revealed full read-and-write access to the platform’s production database, including 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents. ### The Incident Moltbook, dubbed the "front page of the agent internet," gained attention in the AI community for its Reddit-like structure, where AI agents post, comment, and build reputation. However, the platform’s rapid development built entirely through "vibe coding" (AI-generated architecture without manual coding) left security gaps. Researchers identified a hardcoded Supabase API key in the platform’s client-side JavaScript, granting unauthenticated access to the entire database. ### Exposed Data & Risks The breach exposed: - 1.5M API tokens, allowing full account takeovers of any AI agent. - 35,000+ email addresses, including private user data and early-access signups. - 4,060 private messages, some containing plaintext OpenAI API keys. - Write access, enabling attackers to modify posts, inject malicious content, or manipulate platform integrity. The database also revealed that Moltbook’s 1.5 million "AI agents" were largely controlled by just 17,000 human users an 88:1 ratio with no verification to confirm whether agents were truly autonomous. ### Response & Remediation Researchers disclosed the issue to Moltbook’s team, who secured the database within hours. The fix involved enabling Supabase’s Row Level Security (RLS) policies, blocking unauthorized access. The team deleted all accessed data post-remediation. ### Key Takeaways The incident highlights risks in AI-driven development, where speed often outpaces security. Without proper safeguards, even high-profile platforms can expose sensitive data, underscoring the need for secure defaults in AI-built applications. Moltbook’s case serves as a cautionary example for emerging "agent internet" platforms.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 1.5M API tokens, 35,000 email addresses, 4,060 private messages (including plaintext OpenAI API keys)Systems Affected: Moltbook production database, client-side JavaScriptOperational Impact: Potential account takeovers, unauthorized data modification, malicious content injectionBrand Reputation Impact: High (cautionary example for AI-driven platforms)Identity Theft Risk: High (email addresses and API tokens exposed)
DATA BREACH
API tokensEmail addressesPrivate messagesOpenAI API keysNumber Of Records Exposed: 1.5M API tokens, 35,000 email addresses, 4,060 private messagesSensitivity Of Data: High (authentication tokens, plaintext API keys)Personally Identifiable Information: Email addresses
JANUARY 2026
754Before Incident
DECEMBER 2025
754Before Incident
NOVEMBER 2025
754Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Supabase ?
?
What was Supabase's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Supabase's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Supabase's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Supabase's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Supabase ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Supabase's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Supabase Cyber Scoring History | Rankiteo