CVE-2026-31040

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:*

History

25 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Se identificó una vulnerabilidad en stata-mcp anterior a la v1.13.0 donde la validación insuficiente del contenido de archivos do de Stata proporcionados por el usuario puede llevar a la ejecución de comandos.

17 Jun 2026, 10:33

Type Values Removed Values Added
References () https://github.com/SepineTam/stata-mcp/issues/20 - Vendor Advisory, Issue Tracking () https://github.com/SepineTam/stata-mcp/issues/20 - Issue Tracking, Vendor Advisory

14 Apr 2026, 19:31

Type Values Removed Values Added
References () https://github.com/SepineTam/stata-mcp/commit/52413ce - () https://github.com/SepineTam/stata-mcp/commit/52413ce - Patch
References () https://github.com/SepineTam/stata-mcp/issues/20 - () https://github.com/SepineTam/stata-mcp/issues/20 - Vendor Advisory, Issue Tracking
References () https://github.com/SepineTam/stata-mcp/pull/21 - () https://github.com/SepineTam/stata-mcp/pull/21 - Issue Tracking
References () https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0 - () https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0 - Release Notes
CPE cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:*
First Time Statamcp stata-mcp
Statamcp

09 Apr 2026, 21:16

Type Values Removed Values Added
References () https://github.com/SepineTam/stata-mcp/issues/20 - () https://github.com/SepineTam/stata-mcp/issues/20 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

08 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 16:16

Updated : 2026-07-25 10:10


NVD link : CVE-2026-31040

Mitre link : CVE-2026-31040

CVE.ORG link : CVE-2026-31040


JSON object : View

Products Affected

statamcp

  • stata-mcp
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')