Some Supabase customers are publicly exposing reams of people’s data to the web
Supabase customers are accidentally leaking user data at scale—a cautionary tale about how rapid AI-app development and weak configuration compound.

Why it matters
Developers building AI applications with speed-to-market pressure are misconfiguring database access controls, exposing personal data publicly. This is a deployment-practice failure story, not a platform bug—but it signals a broader risk as non-experts ship agentic and AI-driven apps without security review.
The key facts
10 to knowSupabase customers publicly exposing data on the web
Root cause: misconfiguration and weak security practices, not platform vulnerability
Article links the exposure pattern to AI-generated and rapidly coded applications
Highlights risk of 'vibe-coded apps'—applications built fast without proper security architecture
Published Sep 25, 2026
Supabase customers publicly exposing data due to misconfigured access controls
AI-generated and hastily-built applications implicated in data exposure pattern
Issue highlights lack of security configuration in rapid development workflows
Data exposure is preventable through proper row-level security (RLS) and permission boundaries
Published Sep 25, 2026 by TechCrunch
Go to the source
TechCrunch AItechcrunch.com
Publisher excerpt: The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.