BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

MCP Python SDK OAuth flaw lets attackers steal credentials

  • High-severity OAuth credential theft flaw found in MCP Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1.
  • Attacker-controlled MCP server can trick client into sending client secret, authorization code, and PKCE proof key to a malicious endpoint.
  • Fixes released in versions 1.30.0 and 2.2.0; two OAuth providers require additional issuer parameter to be fully secure.
  • Flaw rated 7.5 (high) for machine-to-machine providers, 6.5 for interactive providers; no attacks reported as of September 29.
  • Cycode researchers reported the vulnerability; advisory credits eight reporters.

A critical security flaw in the official MCP Python SDK could allow a malicious MCP server to steal OAuth credentials used to log in to real services, according to a security advisory released on September 28. Affected versions sent the client secret, authorization code, and PKCE proof key to a token endpoint controlled by the attacker rather than the legitimate service.

- Advertisement -

The Model Context Protocol (MCP) is an open standard for connecting AI applications to external tools and data. Cycode, the security firm that reported the flaw, demonstrated the full exchange and confirmed the stolen credentials can generate a valid access token with the app’s granted permissions. The client secret remains valid until manually rotated.

The vulnerability arises because the SDK did not always validate which authorization server the client should use. A malicious server could redirect credentials to an attacker-controlled endpoint while the interactive provider still shows the genuine login page. Fixes are available in version 1.30.0 on the 1.x line and version 2.2.0 on the 2.x line. However, users of ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider must also pass the issuer parameter to tie credentials to a specific login service; without it, the upgrade alone does not prevent the attack.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Can BNB Coin Reclaim $1000 After 45% Slump?

BNB hit an all-time high of $1,369.99 in October 2025 but has since declined...

BTIG Boosts Robinhood Target to $135 on Solid Q3 Metrics

BTIG raised Robinhood's price target to $135 from $125, maintaining a Buy rating with...

Blockchain.com eyes $500M IPO as crypto capital markets thaw

Blockchain.com is reportedly targeting a $500 million initial public offering in 2026, seeking a...

AI agent hack: Australian Senate summons Altman, Amodei

Senator Sarah Hanson-Young invited OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei to...

River sues Blockstream Canada for $6.7M unpaid settlement

River Financial has sued Blockstream Services Canada for defaulting on a $6.7 million settlement...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading