MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Unsanitized tool input can inject Stata shell commands and achieve OS-level RCE on the server account.

10 HIGH · 2 MED · THREAT ORANGE · 12 items · Generated in 237s
Unsanitized tool input can inject Stata shell commands and achieve OS-level RCE on the server account.
Unsanitized MongoDB filters let a low-privileged caller access other tenants' data through injected query operators.
Default SSRF lets attackers read internal services or cloud metadata through the MCP server and expose sensitive data.
Unauthenticated SSRF can reach internal or cloud metadata services and expose response data in affected MLflow versions.
Run creation could bypass assistant ownership checks and expose private assistant metadata across users.
A prompt-injected or malicious MCP client can read or write files the server user can access, including local secrets.
A prompt-injected or malicious MCP client can read or write local files the server user can access.
Unauthenticated path traversal can expose session log files from the server filesystem to any reachable client.
It shows AI agents can expose sensitive data through misconfigured access and unsafe defaults.
Shows enterprises must treat internal AI agents as insider-risk sources and monitor their actions and access.
An AI agent nearly led a user to install malware, showing unsafe package recommendations can cause direct compromise.
Hidden instructions can evade model safeguards and trigger unsafe behavior after decryption in trusted runtime paths.