VDB
Sign up
—

PYSEC-2026-3076

stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution

Quick fix

PYSEC-2026-3076 — stata-mcp: upgrade to the fixed version with the command below.

pip install --upgrade 'stata-mcp>=1.13.0'

Details

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/stata-mcp
Introduced in: 0Fixed in: 1.13.0
Fixpip install --upgrade 'stata-mcp>=1.13.0'

References