AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Studio: Password Manager Can Autofill Account Login Into Database Password Fields

Supabase Studio's database password inputs (Reset database password and new project database password) only set autoComplete="off", which password managers like LastPass ignore. This allows the user's Supabase account password to be autofilled into the database password field, creating a credential reuse vulnerability and potential accidental database password exposure.

highConfidence 87%Next.js

Origin Analysis

The two database password inputs lack the standard password-manager opt-out attributes (autoComplete="new-password", data-1p-ignore, data-lpignore="true", data-form-type="other", data-bwignore) that are already used in other Studio secret fields. Only autoComplete="off" is insufficient because many password managers treat it as a hint, not a directive.
1. Use Chrome with the LastPass extension and a saved login for supabase.com.\n2. Open Project Settings → Database → Reset database password (or create a new project).\n3. Focus the database password field.\n4. LastPass shows its in-field icon and fill menu for the Supabase login and can autofill the account password into the database password field.

Fixing Code Block

Edge Case Audit

While these attributes are widely supported, no method is 100% effective across all password managers or browser versions. Some managers may still prompt to save the generated database password, which could be stored in the vault. If unexpected autofill or save prompts occur, roll back by restoring autoComplete="off" and removing the data-* attributes. Test in multiple browsers and extensions before release. Avoid using autoComplete="off" alone as it is often ignored.

Ecosystem Topology