Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

test new accepts parent-directory names and creates files outside supabase/tests

Open
#6,742 0 comments 0 reactions 1 assignee View on GitHub

@7ttp is already working on this.

Since Sep 23, 2026.

Assessment

This issue has not been assessed yet.

Description

🐛 Bug supabase/cli
Affected area

Database

Supabase CLI version

v2.118.0-beta.67

Operating system

macOS 15.1 (Darwin 24.1.0)

Installation method

npm (npx)

Command
tmp="$(mktemp -d)"
mkdir -p "$tmp/project"

npx --yes --package=supabase@2.118.0-beta.67 -- \
  supabase --workdir "$tmp/project" test new ../../../escaped

test -f "$tmp/escaped_test.sql" && echo "created outside supabase/tests"
Actual output
{"path":"../escaped_test.sql","template":"pgtap","message":""}
created outside supabase/tests

The command exits successfully and creates escaped_test.sql outside the configured workdir. The expected supabase/tests directory is not created.

Expected behavior

test new should reject a name whose normalized output path escapes <workdir>/supabase/tests, exit non-zero, and write nothing outside that directory.

Names containing subdirectories should remain valid if their resolved destination stays within supabase/tests.

Steps to reproduce
  1. Create an empty temporary project directory.
  2. Run supabase test new with ../../../escaped as the test name, as shown above.
  3. Observe that the command reports success.
  4. Observe that the generated file is outside both the configured workdir and supabase/tests.
Crash report ID

No response

Docker and service versions
Not applicable; this command does not use Docker or local services.
Additional context

The handler constructs the destination with path.join("supabase", "tests", name + "_test.sql"). Parent-directory segments are normalized before the write, but the result is not checked against the intended tests directory:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/new.handler.ts#L24-L29

The command's side-effect contract documents writes only under <workdir>/supabase/tests:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/SIDE_EFFECTS.md#files-written

The existing file check prevents overwriting an existing outside file, but the command can create a new file and parent directories outside its documented destination.

supabase migration new already performs an analogous containment check for migration names:

https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/migration/new/new.handler.ts#L36-L46

I searched the current and historical issues and pull requests and did not find an existing report or active fix. I would be happy to contribute a focused fix and integration test after maintainer triage if this is labeled open-for-contribution.

Dominant language
TypeScript
Stars
2.4k
Forks
523
Avg merge
1d 1h
Merged PRs (30d)
268

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from supabase/cli

All issues in supabase/cli

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.