MCP Python SDK OAuth flaw lets malicious servers steal client secrets
A security advisory in the official MCP Python SDK revealed that a malicious MCP server could redirect OAuth discovery and capture an app's client secret, authorization code and PKCE proof key. Affected versions are 1.9.1–1.29.1 (fixed in 1.30.0) and 2.0.0–2.1.1 (fixed in 2.2.0), with CVSS 7.5 for machine-to-machine flows. No CVE has been assigned and no exploitation has been reported.
- Affected versions: 1.9.1–1.29.1 and 2.0.0–2.1.1; fixes in 1.30.0 and 2.2.0
- CVSS 7.5 for machine-to-machine, 6.5 for interactive flows
- ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider require passing issuer=
- Deprecated RFC7523OAuthClientProvider has no issuer= option and must be migrated
Read next
Software