CVE-2026-31040

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:*

History

14 Apr 2026, 19:31

Type Values Removed Values Added
References () https://github.com/SepineTam/stata-mcp/commit/52413ce - () https://github.com/SepineTam/stata-mcp/commit/52413ce - Patch
References () https://github.com/SepineTam/stata-mcp/issues/20 - () https://github.com/SepineTam/stata-mcp/issues/20 - Vendor Advisory, Issue Tracking
References () https://github.com/SepineTam/stata-mcp/pull/21 - () https://github.com/SepineTam/stata-mcp/pull/21 - Issue Tracking
References () https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0 - () https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0 - Release Notes
CPE cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:*
First Time Statamcp stata-mcp
Statamcp

09 Apr 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94
References () https://github.com/SepineTam/stata-mcp/issues/20 - () https://github.com/SepineTam/stata-mcp/issues/20 -

08 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-08 16:16

Updated : 2026-04-14 19:31


NVD link : CVE-2026-31040

Mitre link : CVE-2026-31040

CVE.ORG link : CVE-2026-31040


JSON object : View

Products Affected

statamcp

  • stata-mcp
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')