FindingsReady to scan your own database?
High
Anonymous role granted access to public.webhook_endpoints
- Affected:
- public.webhook_endpoints
- Category:
- Permissions
- Confidence:
- high
- First detected:
- 2026-08-12 11:04Z
- Last verified:
- 2026-08-16 09:41Z
Summary
anon has SELECT, and RLS policies allow access without identity verification.
Why this matters
Anyone with the publishable API key could potentially access this relation without signing in, depending on RLS.
Evidence
- Role
- anon
- Privileges
- SELECT
- RLS Enabled
- true
- Applicable Policy
- Public endpoint directory (USING: true)
Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.
Technical details
RLS is enabled, but a policy applying to anon/PUBLIC has a permissive or easily bypassed USING clause.
Attack path
internet → anon → rest → public.webhook_endpoints
recommended remediation
Unlock Full Audit (Demo)
Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Review anonymous privileges on public.webhook_endpoints.
Current
Role: anon GRANTED PRIVILEGES SELECT granted RLS EFFECTIVE ACCESS RLS ENABLED: true Applicable policies: Public endpoint directory — USING (true)
Recommended Review
Anonymous access is currently permitted. If public access is intentional: • Keep required public policies. • Verify that each policy exposes only intended rows and operations. If public access is not intentional: • Restrict or remove applicable public policies. • Revoke unnecessary anon privileges. Application intent is required before generating a migration.
Expected security effect
- Modifying this could break legitimate public access or Supabase features.
No migration generated — application intent required.
Compatibility risk
high
Any public surface reading this relation without a session will break.
DBX never applies SQL to your database.
