{
  "id": 12130930,
  "title": "3 Supabase RLS Leaks I Found in Production Apps This Week (and the 30-Second Check for Each)",
  "url": "https://urgent.news/2026/10/05/3-supabase-rls-leaks-i-found-in-production-apps-this-week-and-the-30",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-05T10:38:43.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/cekuu35/3-supabase-rls-leaks-i-found-in-production-apps-this-week-and-the-30-second-check-for-each-4pk0"
  },
  "original_language": "en",
  "account": "Three Supabase apps with Row Level Security (RLS) vulnerabilities were discovered this week. Each app had a different issue, but all were due to common mistakes in implementing RLS policies.\n\nPattern 1 involved a helper function that checks if an email exists in the table, effectively opening the entire table to anyone with the anon key. The fix is to wrap the lookup in a function that only returns what's needed, and revoke access to the table for the anon user.\n\nPattern 2 was a policy named \"Users can read all profiles\" that unintentionally granted access to all users, including anon. The issue is that policies without a TO clause apply to public, which includes anon. The solution is to explicitly state the roles the policy applies to.\n\nPattern 3 involved committing the Supabase service role key into the codebase, which made it vulnerable to anyone with access to the code. The recommendation is to rotate the service role key immediately, remove it from the repository, and delete any references to it in the code.",
  "summary": "3 Supabase RLS Leaks I Found in Production Apps This Week (and the 30-Second Check for Each) I audit Supabase apps for a living. This week I read the public source of three real, live products — a university dorm-management system, a freelancing marketplace, and an embedded product configurator — and every single one had a Row Level Security hole that its developer did not know was there. None of…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}