← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Official MCP Python SDK Flaw Allows Malicious Servers to Steal OAuth Credentials

🔄 Updated 3d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Malicious MCP servers could steal OAuth credentials from SDK clients.
  • Affected versions sent client secret, authorization code, and PKCE proof key to attacker-controlled endpoints.
  • Fixes are available in SDK versions 1.30.0 and 2.2.0.
  • The flaw impacts applications connecting to untrusted servers with specific OAuth providers.

Vulnerability Details

The official MCP Python SDK contained a flaw that allowed a malicious MCP server to trick client applications into divulging their OAuth credentials. This vulnerability meant that the client secret, authorization code, and PKCE proof key could be sent to an endpoint controlled by an attacker, rather than the legitimate token endpoint.

The Model Context Protocol (MCP) is an open standard for connecting AI applications to external tools and data. The affected Python SDK is used for building both MCP servers and clients.

Impact of Stolen Credentials

With the stolen credentials, an attacker could request a valid access token from the real login service. Security firm Cycode, which reported the flaw, demonstrated this exchange and confirmed that the resulting token would carry the permissions granted to the compromised application. The client secret is long-lived, remaining valid until it is manually changed.

The flaw received a high severity rating of 7.5 for machine-to-machine providers and 6.5 for interactive providers, where user approval is required. No CVE was assigned as of September 29.

Mechanism of Attack

When an MCP client needed to log in, it queried the server for the location of its authorization server. In affected SDK versions, the client did not always validate this response. A malicious server could provide a fraudulent login service URL, either by directing the client to the attacker's own server or by providing legitimate service details while redirecting credential transmission.

The client would then send its secret, authorization code, and PKCE proof key to the attacker. The PKCE proof key, designed to prevent reuse of stolen authorization codes, was also compromised, negating its protective function.

Affected Applications

Applications are vulnerable if they use the SDK as an MCP client over HTTP with specific OAuth providers: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated 1.x RFC7523OAuthClientProvider. The vulnerability applies when these applications connect to a server they do not fully control while holding credentials for a real login service.

Resolution

The security flaw has been addressed in SDK versions 1.30.0 and 2.2.0. Users of the MCP Python SDK are advised to update to these versions or newer to mitigate the risk of credential theft.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A security flaw in the official MCP Python SDK allowed malicious servers to steal OAuth credentials, including client secrets and authorization codes, from applications. This vulnerability enabled attackers to obtain valid access tokens with the application's permissions, impacting applications using specific OAuth providers over HTTP.