CRITICAL
SepineTam
CVE published 2026-07-21
CVE-2026-47708
MCP-for-Stata is vulnerable to arbitrary Stata command injection due to unsanitized user input in the `log_file_name` parameter of the `stata_do` API and CLI. This issue, patched in version 1.17.3, allows attackers to execute arbitrary Stata commands, including `shell`, `python`, and `erase`, by crafting malicious input containing quotes, newlines, or Stata command separators.