test new accepts parent-directory names and creates files outside supabase/tests
@7ttp is already working on this.
Since Sep 23, 2026.
Assessment
This issue has not been assessed yet.
Description
Affected area
Database
Supabase CLI version
v2.118.0-beta.67
Operating system
macOS 15.1 (Darwin 24.1.0)
Installation method
npm (npx)
Command
tmp="$(mktemp -d)"
mkdir -p "$tmp/project"
npx --yes --package=supabase@2.118.0-beta.67 -- \
supabase --workdir "$tmp/project" test new ../../../escaped
test -f "$tmp/escaped_test.sql" && echo "created outside supabase/tests"
Actual output
{"path":"../escaped_test.sql","template":"pgtap","message":""}
created outside supabase/tests
The command exits successfully and creates escaped_test.sql outside the configured workdir. The expected supabase/tests directory is not created.
Expected behavior
test new should reject a name whose normalized output path escapes <workdir>/supabase/tests, exit non-zero, and write nothing outside that directory.
Names containing subdirectories should remain valid if their resolved destination stays within supabase/tests.
Steps to reproduce
- Create an empty temporary project directory.
- Run
supabase test newwith../../../escapedas the test name, as shown above. - Observe that the command reports success.
- Observe that the generated file is outside both the configured workdir and
supabase/tests.
Crash report ID
No response
Docker and service versions
Not applicable; this command does not use Docker or local services.
Additional context
The handler constructs the destination with path.join("supabase", "tests", name + "_test.sql"). Parent-directory segments are normalized before the write, but the result is not checked against the intended tests directory:
https://github.com/supabase/cli/blob/develop/apps/cli/src/commands/test/new/new.handler.ts#L24-L29
The command's side-effect contract documents writes only under <workdir>/supabase/tests:
The existing file check prevents overwriting an existing outside file, but the command can create a new file and parent directories outside its documented destination.
supabase migration new already performs an analogous containment check for migration names:
I searched the current and historical issues and pull requests and did not find an existing report or active fix. I would be happy to contribute a focused fix and integration test after maintainer triage if this is labeled open-for-contribution.
- Dominant language
- TypeScript
- Stars
- 2.4k
- Forks
- 523
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 268
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from supabase/cli
-
🐛 Bug supabase/cli
-
🐛 Bug supabase/cli
Difficulty 3/5 1-2 days Newbie friendliness 65/100
-
bug supabase/cli
Difficulty 3/5 1-2 days Newbie friendliness 65/100
-
🐛 Bug supabase/cli
Difficulty 3/5 1-2 days Newbie friendliness 65/100
-
🐛 Bug supabase/cli
Similar issues
-
bug(cli): hapi doctor inline-media prints a fabricated B:\ helper-script path in packaged installs Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Crush Open
Difficulty 1/5 Under an hour Newbie friendliness 85/100
catppuccin/catppuccin#3125 ·
-
Add a SECURITY.md Open
Difficulty 1/5 Under an hour Newbie friendliness 90/100
ElementsProject/cln-application#167 · 1 comment · 1 reaction ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Quantco/pnpm-licenses#17 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100