zlacker

[return to "Hacking Moltbook"]
1. gku+XR3[view] [source] 2026-02-03 15:48:38
>>galnag+(OP)
API key exposed in client-side JavaScript X)

> We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovered a Supabase API key exposed in client-side JavaScript, granting unauthenticated access to the entire production database - including read and write operations on all tables.

◧◩
2. r_lee+SY3[view] [source] 2026-02-03 16:15:42
>>gku+XR3
LMAO

how is this even possible? wtf

[go to top]