Function Search Path Mutable in Supabase
Supabase security checks · MEDIUM
The function has no fixed search_path, so it can be tricked into calling the wrong objects.
What goes wrong
A SECURITY DEFINER function in Supabase without a fixed search_path is vulnerable to search path injection. An attacker creates objects in a schema that shadow the objects the function meant to use.
How it happens
The function was created without a SET search_path clause.
How to find it
List the SECURITY DEFINER functions whose configuration has no search_path entry.
SELECT n.nspname AS schema, p.proname AS function_name
FROM pg_proc p
JOIN pg_namespace n ON p.pronamespace = n.oid
WHERE p.prosecdef = true
AND n.nspname NOT IN ('pg_catalog', 'information_schema', 'extensions', 'auth', 'storage', 'pgsodium', 'vault')
AND NOT EXISTS (SELECT 1 FROM unnest(coalesce(p.proconfig, '{}')) c WHERE c LIKE 'search_path=%');How to fix it
Set a fixed search_path on the function.
ALTER FUNCTION public.<function_name> SET search_path = public;
Check your own project
Locksoup runs these checks on your Supabase database in about a minute, with a read-only role, and gives you the SQL to fix what it finds.