Impact
The vulnerability is an unsanitized input in the MCP tool that allows a user to inject newline characters into the package argument, which is concatenated directly into a Stata command string. Because Stata interprets shell escape commands, this injection enables the execution of arbitrary operating‑system commands with the privileges of the Stata‑MCP server process. The resulting impact is full compromise of confidentiality, integrity, and availability of the host system running the server whenever an attacker can invoke the MCP tool or its Python API.
Affected Systems
All installations of SepineTam's MCP‑for‑Stata prior to version 1.19.0 are vulnerable, including all releases in the 1.x series that did not receive the patch included in the 1.19.0 tag.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity RCE. No EPSS value is published, but the lack of a KEV listing does not reduce the likelihood of exploitation; the attacker merely needs to be able to call the MCP tool or API, and the tool is registered in the default profile with no special configuration required. This makes the vulnerability widely exploitable within any environment where the MCP server is reachable by untrusted users.
OpenCVE Enrichment
Github GHSA