FindingsReady to scan your own database?
Low
Anonymous role granted access to realtime.subscription
- Affected:
- realtime.subscription
- Category:
- Permissions
- Confidence:
- medium
- First detected:
- 2026-08-12 11:04Z
- Last verified:
- 2026-08-16 09:41Z
Summary
System/managed schema has anon access, which is usually expected.
Why this matters
Anyone with the publishable API key could potentially access this relation without signing in, depending on RLS.
Evidence
- Role
- anon
- Privileges
- SELECT, INSERT
- RLS Enabled
- false
Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.
Technical details
Supabase manages this schema. Modifying grants here may break internal platform features.
Attack path
internet → anon → rest → realtime.subscription
recommended remediation
Unlock Full Audit (Demo)
Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Review anonymous privileges on realtime.subscription.
Current
Role: anon GRANTED PRIVILEGES SELECT granted INSERT granted RLS EFFECTIVE ACCESS RLS ENABLED: false Applicable policies: None
Recommended Review
Anonymous access is currently permitted. If public access is intentional: • Keep required public policies. • Verify that each policy exposes only intended rows and operations. If public access is not intentional: • Restrict or remove applicable public policies. • Revoke unnecessary anon privileges. Application intent is required before generating a migration.
Expected security effect
- Modifying this could break legitimate public access or Supabase features.
No migration generated — application intent required.
Compatibility risk
high
Any public surface reading this relation without a session will break.
DBX never applies SQL to your database.
