cvedb.io
CVE-2026-31040
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2026-04-08T16:16:22.977 · Last modified 2026-06-17T10:33:18.750

Summary

A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.

Affected products

statamcp — stata-mcp

Does this affect you?

Add your gear to cvedb and we'll alert you only when statamcp ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.