Supabase A.I CyberSecurity Scoring
Supabase
Company Information
Website:https://supabase.com
Employees number:454
Number of followers:118,008
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:supabase.com
Supabase Risk Score (AI oriented)
Between 650 and 699
SupabaseIT Services and IT Consulting
Updated:
26/09/2026
26/09/2026
668/1000
Weak
B
Supabase Global Score (TPRM)
xxxx
SupabaseIT Services and IT Consulting
Score locked

SupabaseWeak
Current Score
668B (WEAK)
01000
3 incidents
-30.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
669
SEPTEMBER 2026
750
Breach
25 Sep 2026 • Supabase
Supabase, Lovable, Replit, Bolt, Indian adult streaming site, U.S. valet parking service and Virtual SIM farm: UpGuard found 16000 Supabase databases leaking user data to the open web
16,000 Supabase Databases Exposed in Mass Misconfiguration Incident
668
CRITICAL-82
INDSUPUP3REPAMETHULOV1790418715
16,000 Supabase Databases Exposed in Mass Misconfiguration Incident
Cybersecurity firm UpGuard uncovered 16,000 publicly exposed Supabase databases leaking sensitive data, including names, passwords, and authentication tokens, according to a TechCrunch report on September 25. The exposed datasets stemmed from misconfigured Postgres row-level security (RLS), a feature designed to restrict database access but left disabled by default in many AI-generated applications.
Supabase, a backend platform widely used by AI coding tools like Lovable, Bolt, and Replit, hosts databases for thousands of apps. However, developers often bypass the platform’s dashboard where RLS is enabled by default when using AI-assisted tools that generate SQL migrations directly. This oversight left databases vulnerable, with no authentication required to access them.
Among the exposed data were private conversations from an Indian adult streaming site, U.S. valet parking license plate records, immigration firm client details, an African consulate’s database, and infrastructure linked to a virtual SIM farm used in account verification scams. In one case, a Lovable-built education platform exposed 18,000 users, including 14,928 email addresses and 870 full personal records, due to a critical RLS failure (CVE-2025-48757, CVSS 8.26).
Supabase’s CISO, Bil Harmer, acknowledged the issue, stating that while the platform provides secure defaults, security remains a shared responsibility with developers. The incident highlights a broader risk: as AI tools automate app development, overlooked security settings like RLS can lead to large-scale exposures when platforms become the default backend for thousands of applications.
Supabase, valued at $10.5 billion after a $500 million funding round in June 2026, serves as a critical infrastructure layer for AI-driven development. The scale of this misconfiguration underscores how default settings in high-adoption platforms can amplify security risks when developers rely on automated workflows.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
747
JULY 2026
747
JUNE 2026
746
MAY 2026
746
APRIL 2026
745
MARCH 2026
745
FEBRUARY 2026
751
Vulnerability
26 Feb 2026 • Supabase
Supabase and Lovable: AI-built app on Lovable exposed 18K users, researcher claims
Lovable Platform Under Fire After AI-Generated App Exposes 18,000 Users’ Data
744
CRITICAL-7
MUSSUP1772216763
Lovable Platform Under Fire After AI-Generated App Exposes 18,000 Users’ Data
A security researcher has uncovered critical vulnerabilities in an app hosted on the AI-driven vibe-coding platform Lovable, exposing the personal data of over 18,000 users, including students and educators from top U.S. universities. Tech entrepreneur Taimur Khan identified 16 flaws six deemed critical in an unnamed app featured on Lovable’s Discover page, which had amassed over 100,000 views and 400 upvotes.
The app, designed for creating exam questions and managing grades, relied on Supabase for authentication and database management. However, due to missing security controls like row-level security (RLS) and role-based access, the AI-generated backend contained logic flaws that inverted access permissions. For example, a malformed authentication function blocked legitimate users while allowing unauthenticated attackers to access sensitive data, delete accounts, alter grades, and extract admin emails.
The exposed dataset included 14,928 unique email addresses, 4,538 student accounts, and 870 records with full personally identifiable information (PII). Users spanned K-12 institutions and universities such as UC Berkeley and UC Davis.
Khan criticized Lovable’s response after his initial report was allegedly closed without action, arguing that the platform should bear responsibility for apps it generates and promotes. Lovable’s CISO, Igor Andriushchenko, countered that the company received a "proper disclosure" only on February 26 and acted within minutes, noting that users are responsible for implementing security recommendations from pre-publish scans. He added that the vulnerable database was not hosted by Lovable and that the app’s creator is now addressing the issues.
The incident highlights broader concerns about AI-generated code, with studies like Veracode’s finding that 45% of such code contains security flaws. While vibe coding named Collins Dictionary’s Word of the Year for 2025 aims to democratize app development, critics warn that unchecked AI tools can produce functional but dangerously insecure software. Lovable has since contacted the app’s owner to mitigate the risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
754
Vulnerability
02 Feb 2026 • Supabase
Supabase and Moltbook: Hacking Moltbook: AI Social Network Reveals 1.5M API Keys
Moltbook: AI Social Network Exposed 1.5M API Tokens in Major Security Flaw
751
CRITICAL-3
SUPPRO1770195532
Moltbook: AI Social Network Exposed 1.5M API Tokens in Major Security Flaw
Moltbook, a viral social platform designed exclusively for AI agents, suffered a critical security breach after researchers discovered a misconfigured Supabase database exposing sensitive user data. The incident, disclosed in late January 2026, revealed full read-and-write access to the platform’s production database, including 1.5 million API authentication tokens, 35,000 email addresses, and private messages between agents.
### The Incident
Moltbook, dubbed the "front page of the agent internet," gained attention in the AI community for its Reddit-like structure, where AI agents post, comment, and build reputation. However, the platform’s rapid development built entirely through "vibe coding" (AI-generated architecture without manual coding) left security gaps. Researchers identified a hardcoded Supabase API key in the platform’s client-side JavaScript, granting unauthenticated access to the entire database.
### Exposed Data & Risks
The breach exposed:
- 1.5M API tokens, allowing full account takeovers of any AI agent.
- 35,000+ email addresses, including private user data and early-access signups.
- 4,060 private messages, some containing plaintext OpenAI API keys.
- Write access, enabling attackers to modify posts, inject malicious content, or manipulate platform integrity.
The database also revealed that Moltbook’s 1.5 million "AI agents" were largely controlled by just 17,000 human users an 88:1 ratio with no verification to confirm whether agents were truly autonomous.
### Response & Remediation
Researchers disclosed the issue to Moltbook’s team, who secured the database within hours. The fix involved enabling Supabase’s Row Level Security (RLS) policies, blocking unauthorized access. The team deleted all accessed data post-remediation.
### Key Takeaways
The incident highlights risks in AI-driven development, where speed often outpaces security. Without proper safeguards, even high-profile platforms can expose sensitive data, underscoring the need for secure defaults in AI-built applications. Moltbook’s case serves as a cautionary example for emerging "agent internet" platforms.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
754
DECEMBER 2025
754
NOVEMBER 2025
754
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Supabase ??
What was Supabase's A.I Rankiteo Cyber Score in September 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in August 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in July 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in June 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in May 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in April 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in March 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in February 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in January 2026 ??
What was Supabase's A.I Rankiteo Cyber Score in December 2025 ??
What was Supabase's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Supabase's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Supabase ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Supabase's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?