chiprook
← Security
SecuritySeptember 29, 2026, 13:08

MCP Python SDK flaw lets malicious servers steal OAuth credentials

A vulnerability in the official MCP Python SDK allowed a malicious MCP server to trick applications into sending their client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint. The issue is fixed in version 1.30.0.

MCP Python SDK flaw lets malicious servers steal OAuth credentials
#MCP
Read next
Security

2,967 MCP servers advertise OAuth; only 8% meet July spec

Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials

Security

Fake Claude Max giveaway steals Google account credentials

Security

Rapuncel Infostealer Disabled 145 Security Tools Before Stealing Credentials