- High-severity OAuth credential theft flaw found in MCP Python SDK versions 1.9.1–1.29.1 and 2.0.0–2.1.1.
- Attacker-controlled MCP server can trick client into sending client secret, authorization code, and PKCE proof key to a malicious endpoint.
- Fixes released in versions 1.30.0 and 2.2.0; two OAuth providers require additional issuer parameter to be fully secure.
- Flaw rated 7.5 (high) for machine-to-machine providers, 6.5 for interactive providers; no attacks reported as of September 29.
- Cycode researchers reported the vulnerability; advisory credits eight reporters.
A critical security flaw in the official MCP Python SDK could allow a malicious MCP server to steal OAuth credentials used to log in to real services, according to a security advisory released on September 28. Affected versions sent the client secret, authorization code, and PKCE proof key to a token endpoint controlled by the attacker rather than the legitimate service.
The Model Context Protocol (MCP) is an open standard for connecting AI applications to external tools and data. Cycode, the security firm that reported the flaw, demonstrated the full exchange and confirmed the stolen credentials can generate a valid access token with the app’s granted permissions. The client secret remains valid until manually rotated.
The vulnerability arises because the SDK did not always validate which authorization server the client should use. A malicious server could redirect credentials to an attacker-controlled endpoint while the interactive provider still shows the genuine login page. Fixes are available in version 1.30.0 on the 1.x line and version 2.2.0 on the 2.x line. However, users of ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider must also pass the issuer parameter to tie credentials to a specific login service; without it, the upgrade alone does not prevent the attack.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
