---
id: CVE-2026-31040
aliases:
  - GHSA-jpcj-7wfg-mqxv
  - PYSEC-2026-3076
title: >-
  stata-mcp has insufficient validation of user-supplied Stata do-file content
  that can lead to command execution
summary: >-
  stata-mcp has insufficient validation of user-supplied Stata do-file content
  that can lead to command execution
severity: high
vendor: stata-mcp
product: stata-mcp
ecosystem: pip
affected:
  - stata-mcp < 1.13.0
patched:
  - stata-mcp 1.13.0
published: '2026-04-08'
updated: '2026-07-13'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jpcj-7wfg-mqxv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-31040'
  - url: 'https://github.com/SepineTam/stata-mcp/issues/20'
  - url: 'https://github.com/SepineTam/stata-mcp/pull/21'
  - url: 'https://github.com/SepineTam/stata-mcp/commit/52413ce'
  - url: 'https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0'
  - url: 'https://github.com/sepinetam/stata-mcp'
tags:
  - osv
  - pip
epss: 0.01063
epssPercentile: 0.63114
ingestedAt: '2026-07-13T18:58:00.041Z'
---

## Overview

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

## Affected packages

- `stata-mcp < 1.13.0`

## Remediation

Upgrade to a patched release:

- `stata-mcp 1.13.0`
