← Reference
Data storage

Anyone visiting your site can read a database table

Row Level Security disabled on exposed table

What this means

Your database is reachable directly from the browser and this table has no row-level access control. Any visitor can download it in full — along with your customers' email addresses and phone numbers.

Why it matters

This is not theoretical: the access key sits in your page source and the download takes a single request. This is exactly how databases behind app-builder projects have leaked.

When this is not a problem

From the outside, 'no access rule' and 'a rule that lets everyone through' look identical — a stranger reads the rows either way. Reference tables and catalogues may be open on purpose.

How to fix it

  • Enable row-level access control on every table holding user data.
  • Write a rule that lets each user see only their own rows.

Prompt for your AI agent

Enable row-level security on the table and add a policy so that each user can only read their own rows.

Verify the fix: query the table without signing in — expect an empty result or a refusal

ClassificationCWE-284CWE-200· API1:2023
Referencescwe.mitre.org
Is your app doing this?
Find out in about a minute — the first scan is free.
Scan your app
Anyone visiting your site can read a database table — seleth