Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
- ID
- 29698
- Status
- summarized
- Published
- 29 Sep 2026, 2:08 PM
- Fetched
- 29 Sep 2026, 3:29 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.0
- Created
- 29 Sep 2026, 3:30 PM
- Tags
- Audience
- developersvibe_codersai_agent_users
What happened
The maintainers of the official MCP Python SDK published a security advisory saying a malicious MCP server could point a client at an attacker-controlled token endpoint, causing the SDK to send the client secret, authorization code, and PKCE proof key to the attacker instead of the real login service. Cycode, which reported the flaw, demonstrated the full exchange in a test and says the resulting access token carries whatever permissions the app was granted; because the client secret is long-lived, it keeps working until changed. Fixed in SDK versions 1.30.0 and 2.2.0; scored 7.5 for the two providers that run without a person present and 6.5 for the interactive provider, with no CVE assigned as of September 29.
Why it matters
If your Python MCP client connects over HTTP using OAuthClientProvider or ClientCredentialsOAuthProvider on a version below 1.30.0/2.2.0, the server you connect to could have redirected your client secret, auth code, and PKCE key to itself — so upgrade, and then rotate the client secret, because the fix does not invalidate a secret that already leaked. Note the interactive case still requires a human to approve a page that Cycode says is the genuine login page, so user approval is not a defence here.
Discussion angle
The SDK trusted the MCP server's answer about where its authorization server lives — no validation of that redirect. Worth walking through how much your agent stack implicitly trusts third-party MCP servers, and whether you'd rotate long-lived client secrets on every MCP server you've ever pointed a client at. The source has no Malaysia-specific angle; the impact is on any team shipping a Python MCP client over HTTP with OAuth.