Please do not open a public issue for security problems.
Report vulnerabilities privately through GitHub: Report a vulnerability.
Include what you found, how to reproduce it, and the impact you expect. We aim to acknowledge reports within a few days and will keep you updated on the fix. We're happy to credit you once it's released.
Security fixes are made on the main branch. Self-hosters should update to the latest release.
Especially interesting:
- Accessing another user's sites, analytics or settings (RLS or authorization bypass)
- Exposure of the service-role key or other secrets to the browser
- Anything that lets the tracker break or run code in a host website
- Storage of data the privacy model says is not stored (e.g. raw IPs)
- Recovering visitor identities from stored hashes
- Sending fake page views to the public ingestion endpoint. It is public by design; see the abuse protections in docs/api.md.
- Rate limits being per server instance (documented).
- Findings that require a compromised Supabase project or server.
- Keep
SUPABASE_SERVICE_ROLE_KEYserver-side only; never prefix it withNEXT_PUBLIC_. - Don't expose the app directly without a proxy that sets
X-Forwarded-Forcorrectly. - Never run
supabase/seed.sqlin production (it creates a demo account with a public password). - Set a long random
CRON_SECRET.