MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Unsanitized MCP input can inject Stata shell commands and execute OS commands as the server user.

2 CRIT · 8 HIGH · 1 MED · 1 INFO · THREAT RED · 12 items · Generated in 234s
Unsanitized MCP input can inject Stata shell commands and execute OS commands as the server user.
Unsanitized MongoDB operators let a low-privileged caller alter queries and expose other tenants' data.
Default SSRF lets attackers fetch internal services or cloud metadata through the server-side URL reader.
Unauthenticated SSRF can reach internal or cloud metadata services and expose response data from MLflow.
Run creation could reference another user's private assistant, bypassing owner checks in affected LangGraph deployments.
A prompt-injected MCP client could read or write files outside the project, exposing secrets or altering local data.
Nested sitemap URLs can bypass domain limits and fetch internal resources, exposing private responses to the caller.
Unauthenticated path traversal can expose session log files and leak sensitive data from the server filesystem.
It highlights multiple active attack paths, including AI-assisted exploit research, that reduce attacker effort and raise real-world risk.
A network-constraining framework may reduce agent misuse, but this item reports a release, not a confirmed vulnerability or active threat.
Exploited MLflow flaws can reach internal endpoints and expose cloud credentials, leading to account takeover and broader compromise.
Active exploitation of a critical MLflow flaw can let attackers compromise AI engineering infrastructure.