/incidents · study · June 2, 2026

Study: 1,072 Supabase-backed apps built with AI tools scanned

Source: Symbiotic Security, June 2, 2026. Written by Lior Aharonov, updated October 3, 2026.

What happened.

Symbiotic Security scanned 1,072 apps that use Supabase, built with Lovable, v0, Bolt.new, Replit and Windsurf.

It reports that 98% had at least one security vulnerability.

308 sites exposed the Supabase anon key in JavaScript, 172 allowed data to be changed or deleted without signing in, and 197 had a CORS misconfiguration on the Supabase API.

This is a study of deployed apps, not a single breach.

Why it happens.

Each builder produces a working app quickly, and the database rules are the part that works in a demo either way. An open table still loads, and a missing policy shows no error. The gap appears only when someone outside the app sends a request the interface never would.

How to check yours in five minutes.

  1. Confirm RLS is on for every table, and read each policy for insert, update and delete as well as select.
  2. Try a write while signed out, from the browser console, against a table that should refuse it.
  3. Check the CORS settings on any API you control.
  4. Search the published scripts for any key other than the public one.
  5. Run the public scan on your app.

Check the public side now.

Ten seconds. We read only what any visitor’s browser already sees, and store nothing.

Opens the app security check on this site with your address filled in.

Source

Symbiotic Security ↗

Published June 2, 2026. Read it in full; this page summarizes only what it reports.