A critical misconfiguration in Moltbook's Supabase database, stemming from an exposed API key in client-side JavaScript and the absence of Row Level Security (RLS), enabled full read and write access. This vulnerability led to the exposure of 1.5 million AI agent authentication tokens, over 64,000 human email addresses, private messages, and allowed unauthenticated modification of platform content.
Why This Matters
Publisher reporting describes a security event affecting over. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether over is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.