{"data":{"id":"413d588f-e167-498f-acb2-9ba74cb79547","title":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials","summary":"A malicious MCP server can trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to a token endpoint the attacker controls. Affected versions are 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and the flaw is rated 7.5 for non-interactive providers and 6.5 for the interactive provider. Cycode reported the issue, and no CVE had been assigned as of September 29, 2026.","solution":"Upgrade to 1.30.0 on the 1.x line or 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, also pass issuer= to name the login service the credentials belong to, since upgrading alone does not fix those providers. Replace the deprecated RFC7523OAuthClientProvider, which has no issuer= option, with one of the other providers. After upgrading, clear stored OAuth client registrations once. If a client may have connected to an untrusted server, rotate its client secret and revoke its tokens at the login service. On older versions, connect only to MCP servers you trust.","labels":["security","industry"],"sourceUrl":"https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html","publishedAt":"2026-09-29T06:08:25.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["MCP Python SDK","Model Context Protocol"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-09-29T06:08:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}