MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
Unsanitized MCP input can inject Stata shell commands and achieve OS-level RCE on the server account.

9 HIGH · 1 MED · 1 LOW · 1 INFO · THREAT ORANGE · 12 items · Generated in 264s
Unsanitized MCP input can inject Stata shell commands and achieve OS-level RCE on the server account.
A low-privileged caller can inject MongoDB operators and read other tenants' data through affected LangChain MongoDB methods.
Default config lets attacker-controlled URLs reach internal services or cloud metadata and expose returned content.
Unauthenticated SSRF can reach internal or cloud metadata endpoints and expose response data on affected MLflow servers.
A user may create runs against another user's private assistant in affected deployments, exposing assistant metadata and bypassing auth checks.
A prompt-injected MCP client can read or overwrite local files the server user can access, exposing secrets or altering system state.
A prompt-injected or malicious MCP client can read or write local files the server user can access.
Unauthenticated path traversal lets attackers read session log .jsonl files and expose potentially sensitive data from the server.
General article on using AI in SOC workflows; no specific vulnerability, attack, or exploit is described.
Security hardening may increase AI operating cost, affecting capacity planning and pricing, but no direct vulnerability is described.
It lowers the barrier to phishing and cybercrime by offering guardrail-free offensive AI to paying users.
Hidden reasoning from stronger models may be recovered via replay, exposing sensitive internal data and weakening provider isolation.