—
PYSEC-2026-3076
stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
Quick fix
PYSEC-2026-3076 — stata-mcp: upgrade to the fixed version with the command below.
pip install --upgrade 'stata-mcp>=1.13.0'Details
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-31040[ADVISORY]
- https://github.com/SepineTam/stata-mcp/issues/20[WEB]
- https://github.com/SepineTam/stata-mcp/pull/21[WEB]
- https://github.com/SepineTam/stata-mcp/commit/52413ce[WEB]
- https://github.com/SepineTam/stata-mcp/releases/tag/v1.13.0[WEB]
- https://github.com/sepinetam/stata-mcp[PACKAGE]
- https://pypi.org/project/stata-mcp[PACKAGE]
- https://github.com/advisories/GHSA-jpcj-7wfg-mqxv[ADVISORY]