{"data":{"id":"68065444-d146-482b-a802-431e5200a248","title":"GHSA-49m4-vp58-wgc9: MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`","summary":"The `ado_package_install` tool in stata-mcp has a command injection vulnerability where user input in the `package` parameter is directly inserted into a Stata command without validation, allowing attackers to inject newline characters and arbitrary Stata commands, including the `shell` command (which runs OS-level code). This leads to RCE (remote code execution, where an attacker can run commands on a system they don't own) with a CVSS score (a 0-10 rating of how severe a vulnerability is) of 8.4 (High), and the tool is enabled by default.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-49m4-vp58-wgc9","publishedAt":"2026-08-12T19:23:38.000Z","cveId":"CVE-2026-55071","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["stata-mcp@< 1.19.0 (fixed: 1.19.0)"],"affectedVendors":[],"affectedVendorsRaw":["Stata","MCP-for-Stata","stata-mcp"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-12T19:23:38.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","availability","confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}