Vibe-Coded Moltbook Exposes User Data, API Keys and More
ID: 06beeb99-eb7f-5e13-a026-7772a038a90c
STIX ID: report--06beeb99-eb7f-5e13-a026-7772a038a90c
Feed Name: Infosecurity Magazine (News)
Wiz Security discovered a Supabase API key exposed in Moltbook’s client-side JavaScript that permitted unauthenticated full read/write access to the production database, exposing 1.5 million API authentication tokens, ~30,000 email addresses, and thousands of private messages; attackers could impersonate agents, post or alter content, and perform prompt-injection attacks. The misconfiguration (missing Row Level Security) was fixed after disclosure; the case highlights risks from rapid “vibe coding” and the need for human security review and proper RLS policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
