Skip to content
MediumNews

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Published
Record updated
View JSON

Summary

A malicious MCP server can trick applications built on the official MCP Python SDK into sending their OAuth client secret, authorization code, and PKCE proof key to a token endpoint the attacker controls. Affected versions are 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and the flaw is rated 7.5 for non-interactive providers and 6.5 for the interactive provider. Cycode reported the issue, and no CVE had been assigned as of September 29, 2026.

Mitigation

Upgrade to 1.30.0 on the 1.x line or 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, also pass issuer= to name the login service the credentials belong to, since upgrading alone does not fix those providers. Replace the deprecated RFC7523OAuthClientProvider, which has no issuer= option, with one of the other providers. After upgrading, clear stored OAuth client registrations once. If a client may have connected to an untrusted server, rotate its client secret and revoke its tokens at the login service. On older versions, connect only to MCP servers you trust.