Supabase MCP agent leaks tokens through a support ticket
A prompt injection in a support ticket made Cursor's agent, connected to Supabase MCP with the service_role key, read an integration tokens table and leak it.
What happened
In July 2025 General Analysis demonstrated an attack on a developer using Cursor with the Supabase MCP server. The attacker submitted a support ticket containing instructions aimed at the agent. When the agent processed the ticket, it followed those instructions.
The agent was connected with the service_role key, which bypasses row-level security. It read a table of integration tokens and leaked its contents to the attacker.
Why it worked
Simon Willison called it a textbook lethal trifecta: private data behind a key that ignores row-level security, untrusted text from customers, and a path for data to leave. Removing any one of the three breaks the attack.
What to do
- Never give an agent the service_role key; connect it read-only and scoped to one project.
- Keep agents that read customer text away from production data.
- Require manual approval for every database tool call.
- Treat ticket and form contents as untrusted input.
Use least-privilege credentialsBreak the lethal trifectaRequire approval for consequential actions
EscapeRoute: Filesystem MCP server sandbox escape
MCP Inspector proxy allowed remote code execution from a browser
Work through the security checklist →