Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A flaw in the official MCP Python SDK could let a malicious MCP server steal OAuth credentials and exchange them for valid access tokens through an attacker-controlled token endpoint. Affected applications should upgrade to versions 1.30.0 or 2.2.0 and, for some providers, also configure the issuer to prevent credential leakage to untrusted servers. #MCPPythonSDK #Cycode #OAuthClientProvider #ClientCredentialsOAuthProvider #PrivateKeyJWTOAuthProvider

Keypoints

  • A malicious MCP server could redirect OAuth traffic to an attacker-controlled endpoint.
  • Affected versions exposed the client secret, authorization code, and PKCE proof key.
  • The stolen credentials could be used to obtain a valid access token from the real service.
  • The flaw affects MCP clients over HTTP using specific OAuth providers in the SDK.
  • Fixes are available in MCP Python SDK 1.30.0 and 2.2.0, with issuer configuration also required for some providers.

Read More: https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html