# Report says DOGE.gov allowed public edits through an insecure database
*Event date: 2025-02-14*
The DOGE.gov website set up to track Elon Musk’s government-cutting initiative was reportedly vulnerable to public edits, according to a report by 404 Media. Two web development experts told the outlet that the site was drawing from a database that third parties could write to, and that changes were showing up live on the page.
The supplied evidence says the site was spun up quickly after Musk said the Department of Government Efficiency would post its actions to X and to the DOGE website. At first, the site was described as almost blank. It was then expanded over the following days to mirror DOGE posts and display workforce statistics. The new report focuses on the security of the underlying infrastructure rather than the content of the page itself.
The striking claim is that anonymous coders were able to add visible entries to the live site. According to the excerpt, at least two database records were inserted: one reading that the site was a joke and another claiming the experts had left the database open. The report says those entries appeared on the public-facing site, which would mean the page was not only exposed but actively accepting unauthorized writes.
404 Media also reported that the site appeared to be built on Cloudflare Pages rather than on government-hosted infrastructure. That detail matters because it raises questions about how the project was deployed and who controlled the systems behind it. The supplied evidence says two people who probed the site independently came to similar conclusions and asked not to be named because they were testing a federal website.
The incident illustrates the speed with which a politically important website can be launched before basic security hardening is complete. If a public-facing database can be modified by outside users, the risk is not just embarrassment. It can undermine trust in the information the site presents, and it can expose any mirrored data or administrative tools behind it to manipulation.
The report does not say whether sensitive data was accessed, only that the database was writable and that changes appeared live. That is still a meaningful security issue. A site built to communicate official actions should not be vulnerable to unauthorized updates, especially when it is associated with federal workforce figures and public statements from a high-profile government-efficiency project.
The evidence also suggests the site was in active development. It had evolved from a blank landing page to a more populated dashboard in a short span of time. Rapid development can explain some rough edges, but it does not excuse a writable database. In security terms, the difference between a page that can be viewed and one that can be edited by outsiders is enormous.
The broader political context makes the problem more sensitive. DOGE was promoted as a transparency effort, with Musk telling reporters that actions would be posted publicly. A site that can be altered by visitors pushes in the opposite direction, because the public cannot easily tell what is authentic and what has been injected by outsiders.
The supplied evidence is limited to the report’s findings, but those findings are clear enough. DOGE.gov was allegedly insecure, was pulling from an editable database and briefly displayed prank records inserted by third parties. That turns a transparency tool into a case study in what happens when speed outruns security.



