Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
AI-summarised brief · reviewed before publication
A security advisory revealed that versions of the official MCP Python SDK could send OAuth credentials—including client secrets, authorization codes, and PKCE proof keys—to a malicious server’s token endpoint. The flaw allows attackers to obtain valid access tokens with the app’s permissions. The issue is fixed in SDK releases 1.30.0 and 2.2.0, but users of certain providers must also specify the issuer to fully mitigate the risk. No attacks have been reported, and the vulnerability is rated high for unattended services.
💡 Why It Matters
- · The flaw exposes a critical backdoor for AI applications to hijack authentication flows, potentially granting attackers broad access to enterprise systems without user intervention.