DBX
DBX home
Acme ProductionPRODUCTIONExit Demo
Run Scan
Findings
Medium

Storage bucket "avatars" is publicly readable

Affected:
storage.avatars
Category:
Storage
Confidence:
high
First detected:
2026-08-12 11:04Z
Last verified:
2026-08-16 09:41Z

Summary

Every object in "avatars" is retrievable by anyone holding the object path.

Why this matters

Public buckets are frequently used for user uploads. Once a path is known or guessable, the object is retrievable indefinitely with no session.

Evidence

Bucket
avatars
public
true
Object policy
Public read → true

Facts above were derived by the scanner from database metadata. No model output is involved in the verdict.

Technical details

storage.buckets.public is true and object policy "Public read" uses an unconditional expression.

recommended remediation

Unlock Full Audit (Demo)

Bottom 35% of Supabase projects we've scanned.
Production-Ready Fixes
Ready to scan your own database?
Buy Remediation Credits — $19

Includes 5 Activation Credits

Make the bucket private and serve objects through signed URLs.

Current

Bucket: avatars Public: true Policies: Public read (SELECT)

Recommended Review

This bucket is currently public. If objects should only be accessed by owners: • Make the bucket private. • Serve objects through signed URLs or create an authenticated RLS policy. Application intent is required before generating a migration.

Expected security effect

  • Anonymous object retrieval removed
  • Access bound to object owner

No migration generated — application intent required.

Compatibility risk

medium

Existing hard-coded public URLs stop resolving. Switch clients to createSignedUrl.

DBX never applies SQL to your database.