CVE-2026-47708
Crafted `log_file_name` in MCP-for-Stata allows arbitrary command execution.
- CVSS 9.3
- CWE-77
- Input Validation and Sanitization
- Remote
MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators. Version 1.17.3 contains a patch for the issue.
- CWE
- CWE-77
- CVSS base score
- 9.3
- Published
- 2026-07-21
- OWASP
- A03 Injection
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Input Validation and Sanitization
- Subcategory
- Command Injection
- Accessibility scope
- Remote
- Impact
- Arbitrary Code Execution
- Fixed by upgrading
- Yes
Solution
Upgrade to MCP-for-Stata version 1.17.3 or later.
Vulnerable code sample
import os
# This code represents the vulnerable logic in the `stata_do` function
# of MCP-for-Stata prior to version 1.17.3.
def create_stata_command(do_file_content, log_file_name):
"""
Simulates the vulnerable command construction.
A security guard (`GuardValidator`) would inspect `do_file_content`
but, as per the CVE, would ignore the `log_file_name`.
"""
# VULNERABILITY: The `log_file_name` parameter is directly interpolated
# into the Stata command string without any sanitization.
stata_command = f'log using "{log_file_name}", replace\n{do_file_content}\nlog close'
# In the actual application, this command would be passed to a Stata process.
# We print the command to demonstrate the successful injection.
print(stata_command)
# Define a benign Stata script content.
safe_stata_script = "sysuse auto, clear\nsummarize mpg"
# An attacker crafts a malicious `log_file_name` to inject an arbitrary command.
# The payload does the following:
# 1. `"`: Closes the opening quote for the `log using` command.
# 2. `;`: Acts as a Stata command separator.
# 3. `shell touch /tmp/pwned`: Injects a shell command to create an empty file.
# 4. `;`: Another command separator.
# 5. `/*`: Starts a Stata block comment to neutralize the rest of the line.
malicious_injection_payload = '"; shell touch /tmp/pwned; /*'
# Demonstrate the vulnerability by calling the function with the malicious payload.
# The output will show the injected `shell` command.
create_stata_command(safe_stata_script, malicious_injection_payload)Patched code sample
import re
def stata_do(do_file_content: str, log_file_name: str):
"""
A representative function demonstrating the fix for CVE-2026-47708.
The vulnerability allowed command injection through an unsanitized
`log_file_name`. The fix involves validating this parameter to ensure
it does not contain characters that could be used to inject arbitrary
Stata commands.
"""
# FIX: Validate the log_file_name to prevent command injection.
# This check disallows characters like quotes and newlines, which an
# attacker could use to break out of the intended command string and
# inject malicious Stata commands (e.g., `shell`, `erase`).
if '"' in log_file_name or '\n' in log_file_name or '\r' in log_file_name:
raise ValueError(
"Invalid log_file_name: Contains characters that could lead to "
"command injection ('\"', '\\n', '\\r')."
)
# After validation, the parameter can be safely used.
# The original vulnerable code would have directly interpolated the
# log_file_name without this validation step.
stata_command = f'log using "{log_file_name}", replace\n'
stata_command += do_file_content
stata_command += '\nlog close'
# In a real application, this command would be sent to a Stata process.
# For this example, we'll just return the safely constructed command.
return stata_commandPayload
pwned.log"
shell touch /tmp/pwned
*
Cite this entry
@misc{vaitp:cve202647708,
title = {{Crafted `log_file_name` in MCP-for-Stata allows arbitrary command execution.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-47708},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-47708/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
