CVE-2026-31040

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/04/2026
Last modified:
14/04/2026

Description

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:statamcp:stata-mcp:*:*:*:*:*:*:*:* 1.13.0 (excluding)