Subscribe Sign in

Some Supabase customers are publicly exposing reams of people’s data to the web

TechCrunch
1 min read Rewritten in plain language

Artificial intelligenceSecurityCybersecurityData ExposureSupabase

Show what we removed Rules applied: A1 A3×2 D2 D3×5 D4×4 F2 all 30 rules
  • Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.
  • Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform.
  • Over the years, data breaches have been linked to improperly configured storage servers, databases and websites.

3 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Server grill with blue light library picture
Not from this story. A library photograph of computer server technology, used to illustrate it. Server grill with blue light bigpresh / flickr, CC BY

Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.

UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases.

Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform.

The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security.

Over the years, data breaches have been linked to improperly configured storage servers, databases and websites.

Shortened to 1 minute of reading, this version reads 13.2 on the Niral Score.

You are reading our version, not theirs. This is TechCrunch's report shortened to its most important sentences, in plainer words, with verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingHappiness
TechCrunchas they published this story 16.7 13 18 51.2
Mundane Readneutralized from TechCrunch 13.6 12 18 51.2

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works