Apps made with AI coding tools expose user data via Supabase

single source· 1 articles · confidence: low · first seen 2026-09-25 17:29 UTC

What this means for you

If you have shipped an app that stores user data on a hosted backend, check whether that data is readable without logging in. The reported failures are configuration, not platform bugs. TechCrunch publishes no list or count of affected projects, so you cannot yet tell whether yours is among them.

TechCrunch reports that some customers of Supabase, the backend service many apps use to hold user data, have left that data publicly readable on the web. The article ties the exposures to AI-generated and "vibe-coded" apps — built by describing what you want to a model rather than writing the code — that were not configured or secured properly. It gives no count of affected customers or records, names no researcher, and does not say whether Supabase or the affected customers have responded.

Key facts

  • ·TechCrunch reported the exposures on 25 September 2026. source
  • ·The affected customers use Supabase, a backend service app developers use to store data. source
  • ·The article attributes the exposures to AI-generated and "vibe-coded" apps that were not configured or secured properly. source
  • ·No figure is given for the number of affected customers or exposed records. source

What the sources say

  • TechCrunch AI — Reports that misconfigured setups at the backend provider are leaving customer data readable online.

Sources

The original reporting. Follow these — they did the work.

← the wire