| Website | https://tmthn.de |
| Codeberg | https://codeberg.org/tmthn |
| Website | https://tmthn.de |
| Codeberg | https://codeberg.org/tmthn |
"Supabase MCP can leak your entire SQL database"
This truly fulfills the AI dream: no more need to know SQL to do SQL injections, no more need to use JavaScript to do XSS - it's all vibes. #AIisgoinggreat
In this post, we show how an attacker can exploit Supabase’s MCP integration to leak a developer’s private SQL tables. Model Context Protocol (MCP) has emerged as a standard way for LLMs to interact with external tools. While this unlocks new capabilities, it also introduces new risk surfaces.