Command Injection Vulnerability in NightTrek Supabase-MCP from NightTrek
CVE-2026-19333
4.8MEDIUM
What is CVE-2026-19333?
A command injection vulnerability has been identified in the NightTrek Supabase-MCP software, specifically within the generate_types component. This flaw allows attackers to manipulate the argument schema, creating a local command injection scenario. Despite early notifications to the project team via an issue report, there has been no response or resolution from their side to mitigate this risk.
Affected Version(s)
Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170
Supabase-MCP db03237d92f7dc2f0da0d70a87dba84ebcde5b66
