{"id":"CVE-2026-55071","published":"2026-09-21T15:17:29.450","lastModified":"2026-09-21T15:17:29.450","description":"MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argument to inject arbitrary Stata commands. Because Stata supports a shell escape command, this leads to full OS-level arbitrary command execution (RCE) under the account running the Stata-MCP server. The tool is registered in the default all profile, so no non-default configuration is required. This issue has been patched in version 1.19.0.","cvssScore":8.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/SepineTam/mcp-for-stata/releases/tag/v1.19.0","tags":[]},{"url":"https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-49m4-vp58-wgc9","tags":[]},{"url":"https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-49m4-vp58-wgc9","tags":[]}],"exploitRefs":[{"url":"https://github.com/SepineTam/mcp-for-stata/releases/tag/v1.19.0","tags":[]},{"url":"https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-49m4-vp58-wgc9","tags":[]},{"url":"https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-49m4-vp58-wgc9","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to inject arbitrary Stata commands by embedding newline characters in package arguments, leading to full OS-level RCE. This matters because it exploits a lack of input validation and can be executed without special configuration.","exploitability":"Exploitation is relatively easy as it requires invoking the MCP tool with malicious input; no complex setup is needed.","blast_radius":"If exploited, this could lead to full system compromise under the Stata-MCP server's account, impacting any systems running such servers.","remediation":"Update to version 1.19.0 or later which includes necessary security patches.","tags":["rce","stata","mcp","os-level","input-validation"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:06:40.187Z"}}