CVE-2026-47708P2CRITICALCVSS 9.3fixed in 1.17.32026-07-21
CVE-2026-47708 [CRITICAL] CWE-77 CVE-2026-47708: MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3,
MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attack
nvd