— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Supabase.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": false,
"average_time_to_bounty_awarded": null,
"average_time_to_first_program_response": 50,
"average_time_to_report_resolved": 1298,
"handle": "supabase",
"id": 0,
"managed_program": false,
"name": "Supabase",
"offers_bounties": false,
"offers_swag": false,
"response_efficiency_percentage": 89,
"submission_state": "open",
"url": "https://hackerone.com/supabase",
"website": "https://supabase.com",
"targets": {
"in_scope": [
{
"asset_identifier": "api.supabase.com",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "https://*.database.dev/",
"asset_type": "WILDCARD",
"availability_requirement": "medium",
"confidentiality_requirement": "medium",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "The database package manager for Trusted Language extensions.",
"integrity_requirement": "medium",
"max_severity": "medium"
},
{
"asset_identifier": "https://github.com/supabase",
"asset_type": "SOURCE_CODE",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "https://github.com/supabase-community/supabase-mcp",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "MCP Server for Supabase integration",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "https://mcp.supabase.com/mcp",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Please consult our docs about this resource: https://supabase.com/docs/guides/getting-started/mcp\n\n`SQL injection` on the `executeSQL` function will not be accepted. This is intended functionality. ",
"integrity_requirement": "high",
"max_severity": "critical"
},
{
"asset_identifier": "https://multiplayer.dev",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "https://nixfbjgqturwbakhnwym.supabase.co\n\nDemo application showcasing Supabase Realtime",
"integrity_requirement": "low",
"max_severity": "low"
},
{
"asset_identifier": "https://supabase.help",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Redirects to the Supabase dashboard for creating support tickets",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "https://supabase.link",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "URL shortener for branded links",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "https://supabase.store",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "Website for purchasing Supabase Swag.",
"integrity_requirement": "medium",
"max_severity": "medium"
},
{
"asset_identifier": "supabase.com",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "high",
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "db.*.supabase.co",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Supabase database domains belonging to our customers.\nTest only domains belonging to your own account. Domains that are part of your account are in-scope",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://*.supabase.co",
"asset_type": "WILDCARD",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Supabase Product APIs and database domains belonging to our customers.\nTest only domains belonging to your own account. Domains that are part of your account are in-scope",
"integrity_requirement": "high",
"max_severity": "none"
},
{
"asset_identifier": "https://api.supabase.com/platform/pg-meta/project_id/query",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is intended to take raw SQL queries. This end-point is not \"SQL injectable\". The ability to escalate privileges via this end-point is a valid issue, but executing SQL is not.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://ctf.supabase.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Capture the Flag leaderboard",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "https://github.com/supabase-community/",
"asset_type": "SOURCE_CODE",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "https://supabase.dev/",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Supabase Contributor Portal - Guide for contributing to Supabase",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "https://supabase.productions/",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "The official Supabase album",
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "supabase.sh",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This allows command execution (ssh supabase.sh) and this is expected behaviour. This is sandboxed and not attached to the Supabase platform in any way",
"integrity_requirement": "none",
"max_severity": "none"
}
]
}
}github.com/supabase-community/supabase-mcp· critical