github

Function Search Path Mutable in Supabase

Supabase security checks · MEDIUM

The function has no fixed search_path, so it can be tricked into calling the wrong objects.

What goes wrong

A SECURITY DEFINER function in Supabase without a fixed search_path is vulnerable to search path injection. An attacker creates objects in a schema that shadow the objects the function meant to use.

How it happens

The function was created without a SET search_path clause.

How to find it

List the SECURITY DEFINER functions whose configuration has no search_path entry.

SELECT n.nspname AS schema, p.proname AS function_name
FROM pg_proc p
JOIN pg_namespace n ON p.pronamespace = n.oid
WHERE p.prosecdef = true
  AND n.nspname NOT IN ('pg_catalog', 'information_schema', 'extensions', 'auth', 'storage', 'pgsodium', 'vault')
  AND NOT EXISTS (SELECT 1 FROM unnest(coalesce(p.proconfig, '{}')) c WHERE c LIKE 'search_path=%');

How to fix it

Set a fixed search_path on the function.

ALTER FUNCTION public.<function_name> SET search_path = public;

Check your own project

Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.

Check my project