Threat Advisory

stata-mcp Vulnerability Allows Complete Endpoint Control

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-55071 with a CVSS score of 8.4 is a code injection vulnerability affecting the stata-mcp package. This flaw exists in the ado_package_install MCP tool, which fails to sanitize user-controlled input before concatenating it directly into a Stata command string. An attacker capable of invoking the MCP tool or the equivalent Python API can exploit this issue by embedding newline characters within the package argument to inject arbitrary Stata commands. Because Stata supports a shell escape command, successful exploitation allows the attacker to achieve full operating system-level arbitrary command execution (RCE) with the privileges of the account running the Stata-MCP server. This capability poses severe business risks, including complete system compromise, data theft, and lateral movement within the environment, as attackers gain unrestricted control over the underlying host. Exploitation requires no non-default configuration since the vulnerable tool is registered in the default all profile, making it readily accessible if the service is exposed.

RECOMMENDATION:

We recommend you to update stata-mcp to version 1.21.4 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-55071 with a CVSS score of 8.4 is a code injection vulnerability affecting the stata-mcp package. This flaw exists in the ado_package_install MCP tool, which fails to sanitize user-controlled input before concatenating it directly into a Stata command string. An attacker capable of invoking the MCP tool or the equivalent Python API can exploit this issue by embedding newline characters within the package argument to inject arbitrary Stata commands. Because Stata supports a shell escape command, successful exploitation allows the attacker to achieve full operating system-level arbitrary command execution (RCE) with the privileges of the account running the Stata-MCP server. This capability poses severe business risks, including complete system compromise, data theft, and lateral movement within the environment, as attackers gain unrestricted control over the underlying host. Exploitation requires no non-default configuration since the vulnerable tool is registered in the default all profile, making it readily accessible if the service is exposed.

RECOMMENDATION:

We recommend you to update stata-mcp to version 1.21.4 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu