Eight Supabase security flaws in AI-built apps that expose user data — and how to audit them
Apps built with AI coding tools like Lovable and Bolt on Supabase may function correctly while silently exposing sensitive user data. In March 2025, a reported vulnerability — later assigned CVE-2025-48757 — revealed that over 170 Lovable-generated apps shipped without effective Row Level Security, leaving emails, payment data, and API keys accessible. Lovable responded with a built-in security scanner in version 2.0, but the scanner only checks whether RLS is enabled, not whether the underlying policies actually restrict data access. A security researcher has identified eight common RLS failure patterns, including user-writable role metadata, disabled RLS on public tables, and overly permissive policies that grant all authenticated users access to all records. Each flaw can be identified within minutes using Supabase's SQL editor, and the researcher recommends developers audit their own projects immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in