Organizations/security vendor

General Analysis

1 records1 attack
Jul 8, 2025
General Analysis shows Supabase MCP with service-role access leaking tables via a support ticket
AttackVulnerability disclosureGeneral Analysis, Supabase

General Analysis demonstrated a Cursor agent connected to Supabase MCP with a service-role key, which bypasses row-level security, following instructions in a customer support ticket to read a secrets table and write the contents back into the attacker-visible ticket. Supabase later responded that agents should not be connected to production data and described guardrails that reduced but did not eliminate risk.