CVE-2026-31040: Statamcp Stata-Mcp

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

Affected products

  • Statamcp Stata-Mcp: before 1.13.0 (fixed in 1.13.0)

Published 2026-04-08. Last modified 2026-07-25.