Critical RCE Vulnerability in MCP-for-Stata: CVE-2026-55071
A critical vulnerability (CVE-2026-55071) has been discovered in MCP-for-Stata, a server for integrating Stata into agent loops. The vulnerability, with a CVSS score of 8.4, allows for arbitrary command execution (RCE) due to improper input validation in the ado_package_install tool. This affects versions prior to 1.19.0 and can be exploited by embedding newline characters in the package argument to inject Stata commands. Immediate patching to version 1.19.0 is recommended.