/incidents · incident · May 29, 2025

CVE-2025-48757: Lovable apps with readable Supabase tables

Source: Superblocks, March 9, 2026. Written by Lior Aharonov, updated October 3, 2026.

What happened.

Matt Palmer found the issue while testing a Lovable-built app called Linkable, then confirmed the same misconfiguration across other projects.

Per Superblocks, 170 projects lacked proper row level security, across 303 endpoints.

The public anon key embedded in each app allowed direct queries to Supabase without signing in, enough to read whole tables.

Palmer reported it privately on 2025-03-21 and published his statement and the CVE entry on 2025-05-29.

Why it happens.

A Supabase app ships its anon key to every browser by design. That is safe only while row level security decides what the key may read. A table created without RLS, or with a policy that allows everyone, is readable by anyone who copies the key from the page.

How to check yours in five minutes.

  1. In Supabase, open Advisors, then Security Advisor, and look for rls_disabled_in_public.
  2. Confirm RLS is enabled on every table in the public schema.
  3. Read each select policy. A condition of true means everyone can read that table.
  4. Search your published app’s scripts for service_role. Only the anon or publishable key belongs there.
  5. Run the public scan on your app.

Check the public side now.

Ten seconds. We read only what any visitor’s browser already sees, and store nothing.

Opens the app security check on this site with your address filled in.

Source

Superblocks ↗

Published March 9, 2026. Read it in full; this page summarizes only what it reports.