HIGH 8.4 GitHub

CVE-2026-55071

MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`

## Stata Command Injection via Unsanitized `package` in `ado_package_install` ### Summary The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the `package` argument to inject arbitrary Stata commands. Because Stata supports a `shell` escape command, this leads to full OS-level arbitrary

Affected Products

References

Published: 2026-08-12 · Source: GitHub · Feed updated: 2026-08-12
This high severity vulnerability with a CVSS score of 8.4 was published on 2026-08-12 via GitHub. Affected: pip/stata-mcp < 1.19.0.
vulnfeed aggregates 10542 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.