Junglewise Threat Intelligence

CVE-2026-31040: SepineTam stata-mcp code injection via Stata do-file shell-escape

CVE-2026-31040 · Severity: critical · CVSS 9.8 · Published 2026-04-08

Technologies: stata-mcp (PyPI). Vendors: PyPI.

Executive brief

stata-mcp, a tool used to integrate Stata data analysis software with other platforms, contains a security flaw that allows for unauthorized command execution. By providing a specially crafted Stata script (do-file), an attacker can bypass security checks to run arbitrary commands on the underlying operating system. This could lead to a complete system takeover, unauthorized data access, or service disruption.

Technical details

A code injection vulnerability (CWE-94) exists in stata-mcp prior to version 1.13.0 due to insufficient validation of user-supplied Stata do-file content. The software failed to block Stata shell-escape directives, such as '!cmd' or 'shell cmd', which allow the Stata interpreter to execute commands directly on the host operating system. An attacker can exploit this by submitting a do-file containing these dangerous tokens, leading to arbitrary command execution with the privileges of the application. The issue was addressed in version 1.13.0 by implementing a validation guard in 'src/stata_mcp/core/stata/stata_do/do.py' that rejects files containing shell-escape sequences.

Affected products

  • SepineTam stata-mcp prior to v1.13.0

Timeline

  • 2025-11-20: patched: Fix merged and version v1.13.0 released
  • 2026-04-08: advisory: CVE-2026-31040 published

References

Related threats