Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Supabase MCP server with service-role key leaks SQL data to a support ticket

General Analysis showed that a customer support ticket containing instructions could make a Cursor agent, connected to Supabase over MCP with a service-role key, dump a secrets table into the ticket thread.

Occurred 3 July 2025 · Disclosed 6 July 2025 · Record updated 13 September 2026

Impact

Integration tokens and other private rows could be exfiltrated. Supabase added a read-only mode, project scoping and prompt-injection warnings to the MCP server.

Our coverage

Sources

  1. generalanalysis.comhttps://www.generalanalysis.com/blog/supabase-mcp-blog
  2. simonwillison.nethttps://simonwillison.net/2025/Jul/6/supabase-mcp-lethal-trifecta/