Ethical Hacking News
Severe Vulnerability Exposed in Official MCP Python SDK: Malicious Servers Can Steal OAuth Credentials. A critical flaw in the official MCP Python SDK allows malicious servers to steal OAuth credentials from unsuspecting applications, highlighting the need for developers to take immediate action to protect their applications.
The MCP Python SDK has a critical flaw that allows malicious servers to steal OAuth credentials from unsuspecting applications. The flaw is in the way the SDK checks the credentials of the server the application is connecting to, allowing attackers to intercept OAuth credentials. The vulnerability is rated high (7.5) for providers that run without a person present, and 6.5 for providers that require human interaction. Developers are advised to upgrade to versions 1.30.0 or 2.2.0 of the MCP Python SDK to mitigate the vulnerability. Upgrading alone is not enough, and developers must also ensure they pass the `issuer` parameter to certain providers and clear stored OAuth client registrations.
The cybersecurity landscape has been dealt a severe blow with the revelation of a critical flaw in the official MCP Python SDK. This open-standard protocol, designed for connecting AI applications to outside tools and data, has been found to contain a glaring vulnerability that allows malicious servers to steal OAuth credentials from unsuspecting applications. The MCP Python SDK is a widely used tool for building MCP servers and clients, and its widespread adoption makes this vulnerability a pressing concern for developers and security professionals alike.
According to the security advisory issued by the SDK's maintainers, the flaw allows a malicious server to trick an application built on the official MCP Python SDK into handing over its OAuth credentials. The affected versions of the SDK, 1.29.1 through 1.30.0, and 2.0.0 through 2.2.0, do not properly check the credentials of the server the application is connecting to, allowing an attacker to intercept the OAuth credentials and use them to request a valid access token from the real login service.
The impact of this vulnerability is significant, as it allows an attacker to gain unauthorized access to a service using the stolen OAuth credentials. The client secret, authorization code, and PKCE proof key are all sent to the token endpoint controlled by the attacker, making it virtually impossible for the application to distinguish between legitimate and malicious requests. This vulnerability is particularly concerning for applications that use OAuth to authenticate users and access external services.
The vulnerability is rated high (7.5) for the two providers that run without a person present, such as the interactive provider, where someone has to start the sign-in process. However, for the providers that require a person to initiate the sign-in, the vulnerability is rated at 6.5. The CVE for this vulnerability has not yet been assigned, and it is not clear when a fix will be available.
Cycode, a security firm that reported the flaw, demonstrated the vulnerability in a test and noted that the resulting token carries whatever permissions the app was granted. The client secret is long-lived, so it keeps working until it is changed, making it essential for developers to take immediate action to protect their applications.
To mitigate this vulnerability, developers are advised to upgrade to versions 1.30.0 or 2.2.0 of the MCP Python SDK. In the fixed versions, the client works out which login service it expects before fetching any details and refuses any that name a different one. However, upgrading alone is not enough, and developers must also ensure that they pass the `issuer` parameter to the `ClientCredentialsOAuthProvider` and `PrivateKeyJWTOAuthProvider` providers to prevent them from following the server's instructions.
In addition to upgrading the SDK, developers should clear any stored OAuth client registrations once, as older registrations are not tied to a login service and will remain unchanged. If a client may have already connected to an untrusted server, developers should rotate its client secret and revoke its tokens at the login service.
The disclosure of this vulnerability serves as a stark reminder of the importance of keeping software up-to-date and thoroughly testing security protocols. The MCP Python SDK is a widely used tool, and its widespread adoption makes it essential for developers and security professionals to take immediate action to protect their applications from this critical flaw.
Related Information:
https://www.ethicalhackingnews.com/articles/Severe-Vulnerability-Exposed-in-Official-MCP-Python-SDK-Malicious-Servers-Can-Steal-OAuth-Credentials-ehn.shtml
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
Published: Tue Sep 29 02:21:46 2026 by llama3.2 3B Q4_K_M