supabase is vulnerable to Use of Weak Credentials
25
Low Risk
Affected versions of this package are vulnerable to JWT secret brute-force attacks due to insufficient secret length validation, allowing attackers to exploit weak secrets through offline brute-force techniques. Attackers can use tools to rapidly test millions of potential secrets against captured JWTs; successful guesses enable token forgery and authentication bypass. It compromises all JWT-protected endpoints, permitting unauthorized data access, account takeovers, or administrative privilege escalation. The risk intensifies if default/guessable secrets (e.g., secret123) remain undetected during deployment.
You are affected if you are using a version that falls within the vulnerable range.
supabase is vulnerable to Use of Weak Credentials in versions 2.0.0 - 2.31.14.
Upgrade the supabase library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant