{"id":"CVE-2026-31040","aliases":["GHSA-jpcj-7wfg-mqxv","PYSEC-2026-3076"],"title":"stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution","summary":"stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution","severity":"high","vendor":"stata-mcp","product":"stata-mcp","ecosystem":"pip","affected":["stata-mcp < 1.13.0"],"patched":["stata-mcp 1.13.0"],"published":"2026-04-08","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jpcj-7wfg-mqxv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31040"},{"url":"https://github.com/SepineTam/stata-mcp/issues/20"},{"url":"https://github.com/SepineTam/stata-mcp/pull/21"},{"url":"https://github.com/SepineTam/stata-mcp/commit/52413ce"},{"url":"https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0"},{"url":"https://github.com/sepinetam/stata-mcp"}],"tags":["osv","pip"],"epss":0.00557,"epssPercentile":0.45276,"ingestedAt":"2026-07-13T18:58:00.041Z","slug":"CVE-2026-31040","body":"## Overview\n\nA vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.\n\n## Affected packages\n\n- `stata-mcp < 1.13.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `stata-mcp 1.13.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}