chiprook
← Security
SecurityOctober 2, 2026, 07:28

MCP Python SDK OAuth flaw lets malicious servers steal client secrets

A security advisory in the official MCP Python SDK revealed that a malicious MCP server could redirect OAuth discovery and capture an app's client secret, authorization code and PKCE proof key. Affected versions are 1.9.1–1.29.1 (fixed in 1.30.0) and 2.0.0–2.1.1 (fixed in 2.2.0), with CVSS 7.5 for machine-to-machine flows. No CVE has been assigned and no exploitation has been reported.

MCP Python SDK OAuth flaw lets malicious servers steal client secrets
#MCP
Read next
Software

Codex CLI 0.158: approval for elevated commands and MCP OAuth client secrets

Security

Unsloth Studio flaw let malicious AI models run Python code on inspection

Security

Malicious AI agents steal 600K credit cards, infect 119 sites with skimmers

Security

Malicious npm Package Poses as Twilio Security Tool, Steals Credentials