AI Weekly Malaysia

Back to items Summaries

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

ID
29698
Status
summarized
Published
29 Sep 2026, 2:08 PM
Fetched
29 Sep 2026, 3:29 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.0
Created
29 Sep 2026, 3:30 PM
Tags
Audience
developersvibe_codersai_agent_users

What happened

The maintainers of the official MCP Python SDK published a security advisory saying a malicious MCP server could point a client at an attacker-controlled token endpoint, causing the SDK to send the client secret, authorization code, and PKCE proof key to the attacker instead of the real login service. Cycode, which reported the flaw, demonstrated the full exchange in a test and says the resulting access token carries whatever permissions the app was granted; because the client secret is long-lived, it keeps working until changed. Fixed in SDK versions 1.30.0 and 2.2.0; scored 7.5 for the two providers that run without a person present and 6.5 for the interactive provider, with no CVE assigned as of September 29.

Why it matters

If your Python MCP client connects over HTTP using OAuthClientProvider or ClientCredentialsOAuthProvider on a version below 1.30.0/2.2.0, the server you connect to could have redirected your client secret, auth code, and PKCE key to itself — so upgrade, and then rotate the client secret, because the fix does not invalidate a secret that already leaked. Note the interactive case still requires a human to approve a page that Cycode says is the genuine login page, so user approval is not a defence here.

Discussion angle

The SDK trusted the MCP server's answer about where its authorization server lives — no validation of that redirect. Worth walking through how much your agent stack implicitly trusts third-party MCP servers, and whether you'd rotate long-lived client secrets on every MCP server you've ever pointed a client at. The source has no Malaysia-specific angle; the impact is on any team shipping a Python MCP client over HTTP with OAuth.

Top