A critical command injection flaw in SepineTam's mcp-for-stata exposed the stata_do API and CLI to remote code execution by interpolating the user-controlled log_file_name parameter directly into a Stata command string without sanitization. The issue reportedly affects versions through v1.17.2 and impacts both Unix-like and Windows execution paths in src/stata_mcp/stata/stata_do/do.py. Researchers said the project's GuardValidator did not stop the attack because it inspected only do-file content, not wrapper parameters, allowing attackers to inject Stata commands such as shell, python, or erase and potentially execute host-level commands.
The vulnerability also introduced a path traversal risk because crafted log names could escape the intended log directory and overwrite arbitrary files. A GitHub advisory and issue report included proof-of-concept abuse showing a malicious log_file_name could trigger shell execution and write to files such as /tmp/pwned.txt, while warning that dofile_path may carry similar injection risk because it is also embedded in a command string. A subsequent fix added regex-based validation for log_file_name, restricted names to 1-128 characters from a safe allowlist, blocked empty path components and . or .., and moved log path generation into a helper function, though the Windows code path still retains shell=True for Stata startup and path resolution.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A code commit added regex-based validation for log_file_name, restricted it to a safe character set and length, and blocked empty path components plus '.' and '..'. The change also routed log path creation through a helper method instead of directly interpolating the filename into command construction.
A GitHub issue and advisory disclosed a command injection vulnerability in the stata_do API and CLI, where the user-controlled log_file_name parameter was interpolated into a Stata command string without sanitization. The report said the flaw affected versions up to v1.17.2 and could enable remote code execution and path traversal.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.