Security Vulnerability in Supabase MCP Could Lead to Database Leakage
By
rexpository
10mo ago· 2 min readenNews
75/100
Toasty
Bagelometer↗
Warm and crisp on the edges. A bagel with a bit of bite.
Score75TypenewsSentimentnegative
Summary
The article discusses a potential security vulnerability in Supabase MCP that could lead to the leakage of an entire SQL database through a trifecta attack.
Key quotes
· 2 pulledHere's yet another example of a lethal trifecta attack, where an LLM system combines access to private data, exposure to potentially malicious instructions and a mechanism to communicate data back out to an attacker.
They imagine a scenario where a developer asks Cursor, running the Supabase MCP, to "use cursor’s agent to list the latest support tickets"
Here's yet another example of a lethal trifecta attack, where an LLM system combines access to private data, exposure to potentially malicious instructions and a mechanism to communicate data back …
