---
title: "Supabase MCP agent leaks tokens through a support ticket · DotsAgent"
description: "A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it."
url: https://dotsagent.io/security/incidents/2025-07-supabase-mcp-token-leak
---

July 2025

# Supabase MCP agent leaks tokens through a support ticket

A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.

## What happened

In July 2025 General Analysis demonstrated an attack on a developer using Cursor with the Supabase MCP server. The attacker submitted a support ticket containing instructions aimed at the agent. When the agent processed the ticket, it followed those instructions.

The agent was connected with the service_role key, which bypasses row-level security. It read a table of integration tokens and leaked its contents to the attacker.

## Why it worked

Simon Willison called it a textbook lethal trifecta: private data behind a key that ignores row-level security, untrusted text from customers, and a path for data to leave. Removing any one of the three breaks the attack.

## What to do

- Never give an agent the service_role key; connect it read-only and scoped to one project.
- Keep agents that read customer text away from production data.
- Require manual approval for every database tool call.
- Treat ticket and form contents as untrusted input.

[Use least-privilege credentials](https://dotsagent.io/security#leastPrivilege)[Break the lethal trifecta](https://dotsagent.io/security#lethalTrifecta)[Require approval for consequential actions](https://dotsagent.io/security#humanApproval)

- [EscapeRoute: Filesystem MCP server sandbox escape](https://dotsagent.io/security/incidents/2025-07-filesystem-mcp-escaperoute)

- [MCP Inspector proxy allowed remote code execution from a browser](https://dotsagent.io/security/incidents/2025-06-mcp-inspector-rce)

[Work through the security checklist →](https://dotsagent.io/security/checklist)

## Sources

1. [generalanalysis.com](https://generalanalysis.com/blog/supabase-mcp-blog)/blog/supabase-mcp-blog
2. [simonwillison.net](https://simonwillison.net/2025/Jul/6/supabase-mcp-lethal-trifecta/)/2025/Jul/6/supabase-mcp-lethal-trifecta/

Independent reference for people who build AI agents. Not affiliated with any vendor named here.

© 2026 DotsAgent · Facts checked October 1, 2026
