Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper
Vulnerability Description
MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` parameter in the `stata_do` API and CLI is directly interpolated into a Stata command string without sanitization. The security guard (`GuardValidator`) only scans the do-file content but does not validate this parameter. An attacker can inject arbitrary Stata commands (including `shell`, `python`, `erase`, etc.) by crafting a malicious `log_file_name` containing quotes, newlines, or Stata command separators. Version 1.17.3 contains a patch for the issue.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
S.Tam MCP-for-Stata 命令注入漏洞
Vulnerability Description
S.Tam MCP-for-Stata是美国S.Tam个人开发者的一款用于将 Stata 集成到代理中的 MCP 服务器。 S.Tam MCP-for-Stata 1.17.3之前版本存在命令注入漏洞,该漏洞源于在stata_do API和CLI中的`log_file_name`参数直接插入到Stata命令字符串中且未进行清理,攻击者可通过构造恶意的`log_file_name`注入任意Stata命令。
CVSS Information
N/A
Vulnerability Type
N/A