Command Injection Vulnerability in NightTrek Supabase-MCP from NightTrek
CVE-2026-19333

4.8MEDIUM

Key Information:

Vendor

Nighttrek

Vendor
CVE Published:
9 August 2026

What is CVE-2026-19333?

A command injection vulnerability has been identified in the NightTrek Supabase-MCP software, specifically within the generate_types component. This flaw allows attackers to manipulate the argument schema, creating a local command injection scenario. Despite early notifications to the project team via an issue report, there has been no response or resolution from their side to mitigate this risk.

Affected Version(s)

Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170

Supabase-MCP db03237d92f7dc2f0da0d70a87dba84ebcde5b66

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

gongyanyu04 (VulDB User)
VulDB CNA Team
.