The official MCP Python SDK contained a flaw that allowed a malicious MCP server to trick client applications into divulging their OAuth credentials. This vulnerability meant that the client secret, authorization code, and PKCE proof key could be sent to an endpoint controlled by an attacker, rather than the legitimate token endpoint.
The Model Context Protocol (MCP) is an open standard for connecting AI applications to external tools and data. The affected Python SDK is used for building both MCP servers and clients.
With the stolen credentials, an attacker could request a valid access token from the real login service. Security firm Cycode, which reported the flaw, demonstrated this exchange and confirmed that the resulting token would carry the permissions granted to the compromised application. The client secret is long-lived, remaining valid until it is manually changed.
The flaw received a high severity rating of 7.5 for machine-to-machine providers and 6.5 for interactive providers, where user approval is required. No CVE was assigned as of September 29.
When an MCP client needed to log in, it queried the server for the location of its authorization server. In affected SDK versions, the client did not always validate this response. A malicious server could provide a fraudulent login service URL, either by directing the client to the attacker's own server or by providing legitimate service details while redirecting credential transmission.
The client would then send its secret, authorization code, and PKCE proof key to the attacker. The PKCE proof key, designed to prevent reuse of stolen authorization codes, was also compromised, negating its protective function.
Applications are vulnerable if they use the SDK as an MCP client over HTTP with specific OAuth providers: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated 1.x RFC7523OAuthClientProvider. The vulnerability applies when these applications connect to a server they do not fully control while holding credentials for a real login service.
The security flaw has been addressed in SDK versions 1.30.0 and 2.2.0. Users of the MCP Python SDK are advised to update to these versions or newer to mitigate the risk of credential theft.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A security flaw in the official MCP Python SDK allowed malicious servers to steal OAuth credentials, including client secrets and authorization codes, from applications. This vulnerability enabled attackers to obtain valid access tokens with the application's permissions, impacting applications using specific OAuth providers over HTTP.