Sceawere

Vulnerability Detail

CVE-2026-19333UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

NightTrek Supabase-MCP Command Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
5h ago
Vendor
NightTrek
Product
Supabase-MCP
Attack Type
Command Injection
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be approached locally. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-09T05:16:51.207Z",
  "pubdate": "2026-08-09T05:16:51.207Z",
  "executiveSummary": "A command injection vulnerability has been identified within the NightTrek Supabase-MCP repository, specifically affecting commit ranges between cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170 and db03237d92f7dc2f0da0d70a87dba84ebcde5b66.\nThe vulnerability resides within the generate_types component, where improper handling of the schema argument allows malicious input to execute arbitrary operating system commands.\nSuccessful exploitation of this flaw leads to remote or local command execution under the security context of the application process.\nThe attack vector requires local access to the system and manipulation of the targeted argument.\nThe risk implication is severe, potentially compromising the integrity, confidentiality, and availability of the host system.\nThe vendor has been notified via an issue report but has not yet provided a response or official patch.",
  "technicalDetails": "The vulnerability is classified as a command injection flaw occurring within the generate_types component of the NightTrek Supabase-MCP project.\nThe root cause stems from the insecure execution of underlying system shells or processes where input supplied via the schema argument is concatenated or passed without adequate sanitization, validation, or escaping.\nAffected versions include commits cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170 through db03237d92f7dc2f0da0d70a87dba84ebcde5b66.\nThe attack flow proceeds as follows: an attacker with local access interacts with the generate_types component, supplying a crafted payload engineered specifically within the schema argument parameter.\nBecause the application fails to properly sanitize this input before passing it to a system command execution sink (such as shell execution functions), the injected characters break out of the intended argument context.\nThis allows the operating system shell to interpret the injected payload as discrete commands, executing them sequentially or conditionally depending on the syntax used.\nAuthentication and privilege requirements depend on the local execution context of the application, but successful exploitation grants the privileges associated with the running process.\nNetwork exposure is localized due to the local attack vector requirement, but local execution can cascade into broader system compromise.\nPost-exploitation impact includes arbitrary command execution, data exfiltration, modification of system files, and further lateral movement within the underlying host environment."
}
CVE-2026-19333: NightTrek Supabase-MCP Command Injection (MEDIUM Severity, CVSS: 5.3) - Sceawere