Description
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argument to inject arbitrary Stata commands. Because Stata supports a shell escape command, this leads to full OS-level arbitrary command execution (RCE) under the account running the Stata-MCP server. The tool is registered in the default all profile, so no non-default configuration is required. This issue has been patched in version 1.19.0.
Published: 2026-09-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is an unsanitized input in the MCP tool that allows a user to inject newline characters into the package argument, which is concatenated directly into a Stata command string. Because Stata interprets shell escape commands, this injection enables the execution of arbitrary operating‑system commands with the privileges of the Stata‑MCP server process. The resulting impact is full compromise of confidentiality, integrity, and availability of the host system running the server whenever an attacker can invoke the MCP tool or its Python API.

Affected Systems

All installations of SepineTam's MCP‑for‑Stata prior to version 1.19.0 are vulnerable, including all releases in the 1.x series that did not receive the patch included in the 1.19.0 tag.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity RCE. No EPSS value is published, but the lack of a KEV listing does not reduce the likelihood of exploitation; the attacker merely needs to be able to call the MCP tool or API, and the tool is registered in the default profile with no special configuration required. This makes the vulnerability widely exploitable within any environment where the MCP server is reachable by untrusted users.

Generated by OpenCVE AI on September 21, 2026 at 15:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply version 1.19.0 or later of MCP‑for‑Stata, which removes the unsanitized string concatenation.
  • Limit the ability of untrusted users or remote clients to invoke the ado_package_install command by restricting permissions on the MCP control interface or by isolating the API behind a firewall or access control policy.
  • If an upgrade cannot be performed immediately, configure the host to drop the Stata‑MCP server’s privileges to those required for user analysis only, and/or deny the shell‑escape capability in Stata or block it via SELinux/AppArmor rules.

Generated by OpenCVE AI on September 21, 2026 at 15:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-49m4-vp58-wgc9 MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Sepinetam
Sepinetam mcp-for-stata
Vendors & Products Sepinetam
Sepinetam mcp-for-stata

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argument to inject arbitrary Stata commands. Because Stata supports a shell escape command, this leads to full OS-level arbitrary command execution (RCE) under the account running the Stata-MCP server. The tool is registered in the default all profile, so no non-default configuration is required. This issue has been patched in version 1.19.0.
Title MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Sepinetam Mcp-for-stata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T14:56:37.752Z

Reserved: 2026-06-16T14:33:35.710Z

Link: CVE-2026-55071

cve-icon Vulnrichment

Updated: 2026-09-21T14:56:31.832Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-21T15:17:29.450

Modified: 2026-09-24T21:17:43.237

Link: CVE-2026-55071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:23:45Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')