{"id":"CVE-2026-47708","aliases":["GHSA-4p62-hqp5-g644","PYSEC-2026-544"],"url":"https://o3.security/vulnerability/CVE-2026-47708","summary":"MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper","details":"MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators. Version 1.17.3 contains a patch for the issue.","published":"2026-07-21T20:55:15.048Z","modified":"2026-08-12T03:51:28.280310549Z","cvss":null,"epss":{"score":0.00525,"percentile":0.4214,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"stata-mcp","fixedVersion":"1.17.3"}],"fix":{"url":"https://github.com/SepineTam/mcp-for-stata/commit/e6f945941ae0c7cf5e74a428e0b3dc82b396382f","label":"SepineTam/mcp-for-stata@e6f9459"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47708.json"},{"type":"ADVISORY","url":"https://github.com/SepineTam/mcp-for-stata/security/advisories/GHSA-4p62-hqp5-g644"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47708"},{"type":"REPORT","url":"https://github.com/SepineTam/mcp-for-stata/issues/74"},{"type":"FIX","url":"https://github.com/SepineTam/mcp-for-stata/commit/e6f945941ae0c7cf5e74a428e0b3dc82b396382f"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:28.280310549Z"}}