Supabase provides an open-source backend-as-a-service platform centered on PostgreSQL integration and authentication, with a focused vulnerability profile around its auth and database-connectivity components. The observed weaknesses center on authentication-bypass conditions and SQL-injection issues, reflecting the authentication and database-query parsing demands of the platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Supabase over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24213CRITICAL Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended | Feb 8, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-31813MEDIUM Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been identified that allows an attacker to issue sessions for arbi | Mar 11, 2026 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Supabase.
Media articles that mention a CVE ID that affects a product developed by Supabase — matched by CVE ID, not by vendor name.