MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Unsanitized MCP input enables OS command execution on the Stata-MCP host under the server account.

9 HIGH · 1 MED · 2 INFO · THREAT ORANGE · 12 items · Generated in 249s
Unsanitized MCP input enables OS command execution on the Stata-MCP host under the server account.
A crafted MongoDB filter can bypass tenant boundaries and expose other customers' data through affected library methods.
Default SSRF lets attacker-controlled URLs reach internal services or cloud metadata and return the data.
Unauthenticated SSRF can hit internal or cloud metadata services and expose response data through the webhook test endpoint.
A user could create runs against another user's private assistant and expose its metadata due to missing auth checks.
A prompt-injected or malicious MCP client can read or write files outside the project, exposing secrets or altering local system state.
A prompt-injected tool call could read or write any file the MCP server user can access on the local system.
Unauthenticated path traversal can expose session log files and leak sensitive data from the host filesystem.
Trojanized npm packages can silently install a Linux backdoor, turning dependency installs into host compromise.
This is a standards and awareness update, not a reported exploit or vulnerability affecting systems.
Attackers are using AI-generated code against critical infrastructure controllers, showing real operational risk to essential systems.
This is a partner award announcement, not a vulnerability or incident, so it has no direct security impact.