A misconfigured Supabase database, with an exposed API key in client-side JavaScript and disabled Row Level Security (RLS), granted unauthenticated full read and write access to the Moltbook platform's production data. This vulnerability resulted in the exfiltration of 1.5 million API authentication tokens, over 64,000 email addresses, private messages containing third-party API credentials, and enabled unauthorized content modification.
Why This Matters
Publisher reporting describes a security event affecting over. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether over is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.