A flaw in the official MCP Python SDK could let a malicious MCP server steal OAuth credentials and exchange them for valid access tokens through an attacker-controlled token endpoint. Affected applications should upgrade to versions 1.30.0 or 2.2.0 and, for some providers, also configure the issuer to prevent credential leakage to untrusted servers. #MCPPythonSDK #Cycode #OAuthClientProvider #ClientCredentialsOAuthProvider #PrivateKeyJWTOAuthProvider
Keypoints
- A malicious MCP server could redirect OAuth traffic to an attacker-controlled endpoint.
- Affected versions exposed the client secret, authorization code, and PKCE proof key.
- The stolen credentials could be used to obtain a valid access token from the real service.
- The flaw affects MCP clients over HTTP using specific OAuth providers in the SDK.
- Fixes are available in MCP Python SDK 1.30.0 and 2.2.0, with issuer configuration also required for some providers.
Read More: https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html