zlacker

[parent] [thread] 1 comments
1. gku+(OP)[view] [source] 2026-02-03 15:48:38
API key exposed in client-side JavaScript X)

> We conducted a non-intrusive security review, simply by browsing like normal users. Within minutes, we discovered a Supabase API key exposed in client-side JavaScript, granting unauthenticated access to the entire production database - including read and write operations on all tables.

replies(1): >>r_lee+V6
2. r_lee+V6[view] [source] 2026-02-03 16:15:42
>>gku+(OP)
LMAO

how is this even possible? wtf

[go to top]