CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-31040

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-94

Description

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

Affected packages

PyPI stata-mcp 0 → 1.13.0

References

Status: profiled · ingested 2026-07-25T12:00:18.000Z