CVE-2026-31040
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-94
Description
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
Affected packages
| PyPI | stata-mcp | 0 → 1.13.0 |
References
Status: profiled · ingested 2026-07-25T12:00:18.000Z