VAITP Dataset

← Back to the dataset

CVE-2026-47708

Crafted `log_file_name` in MCP-for-Stata allows arbitrary command execution.

  • CVSS 9.3
  • CWE-77
  • Input Validation and Sanitization
  • Remote

MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators. Version 1.17.3 contains a patch for the issue.

CVSS base score
9.3
Published
2026-07-21
OWASP
A03 Injection
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Input Validation and Sanitization
Subcategory
Command Injection
Accessibility scope
Remote
Impact
Arbitrary Code Execution
Fixed by upgrading
Yes

Solution

Upgrade to MCP-for-Stata version 1.17.3 or later.

Vulnerable code sample

import os

# This code represents the vulnerable logic in the `stata_do` function
# of MCP-for-Stata prior to version 1.17.3.
def create_stata_command(do_file_content, log_file_name):
    """
    Simulates the vulnerable command construction.
    A security guard (`GuardValidator`) would inspect `do_file_content`
    but, as per the CVE, would ignore the `log_file_name`.
    """

    # VULNERABILITY: The `log_file_name` parameter is directly interpolated
    # into the Stata command string without any sanitization.
    stata_command = f'log using "{log_file_name}", replace\n{do_file_content}\nlog close'

    # In the actual application, this command would be passed to a Stata process.
    # We print the command to demonstrate the successful injection.
    print(stata_command)


# Define a benign Stata script content.
safe_stata_script = "sysuse auto, clear\nsummarize mpg"

# An attacker crafts a malicious `log_file_name` to inject an arbitrary command.
# The payload does the following:
# 1. `"`: Closes the opening quote for the `log using` command.
# 2. `;`: Acts as a Stata command separator.
# 3. `shell touch /tmp/pwned`: Injects a shell command to create an empty file.
# 4. `;`: Another command separator.
# 5. `/*`: Starts a Stata block comment to neutralize the rest of the line.
malicious_injection_payload = '"; shell touch /tmp/pwned; /*'

# Demonstrate the vulnerability by calling the function with the malicious payload.
# The output will show the injected `shell` command.
create_stata_command(safe_stata_script, malicious_injection_payload)

Patched code sample

import re

def stata_do(do_file_content: str, log_file_name: str):
    """
    A representative function demonstrating the fix for CVE-2026-47708.

    The vulnerability allowed command injection through an unsanitized
    `log_file_name`. The fix involves validating this parameter to ensure
    it does not contain characters that could be used to inject arbitrary
    Stata commands.
    """

    # FIX: Validate the log_file_name to prevent command injection.
    # This check disallows characters like quotes and newlines, which an
    # attacker could use to break out of the intended command string and
    # inject malicious Stata commands (e.g., `shell`, `erase`).
    if '"' in log_file_name or '\n' in log_file_name or '\r' in log_file_name:
        raise ValueError(
            "Invalid log_file_name: Contains characters that could lead to "
            "command injection ('\"', '\\n', '\\r')."
        )

    # After validation, the parameter can be safely used.
    # The original vulnerable code would have directly interpolated the
    # log_file_name without this validation step.
    stata_command = f'log using "{log_file_name}", replace\n'
    stata_command += do_file_content
    stata_command += '\nlog close'

    # In a real application, this command would be sent to a Stata process.
    # For this example, we'll just return the safely constructed command.
    return stata_command

Payload

pwned.log"
shell touch /tmp/pwned
*

Cite this entry

@misc{vaitp:cve202647708,
  title        = {{Crafted `log_file_name` in MCP-for-Stata allows arbitrary command execution.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-47708},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-47708/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::