MCP SDK OAuth fix audit: patching alone leaves the hole open
On September 28 the MCP Python SDK shipped a fix for credential-theft bug GHSA-qx49-fqc8-xw99 (CVSS 7.5): a malicious MCP server could steer OAuth discovery and capture the client_secret, authorization code and PKCE code_verifier. Upgrading to 1.30.0 or 2.2.0 is not enough unless ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider are constructed with an explicit issuer.
- Advisory GHSA-qx49-fqc8-xw99 carries a CVSS 3.1 score of 7.5
- Patched releases 1.30.0 and 2.2.0 hit PyPI on September 7
- Without issuer= the credential-theft path stays open after upgrade
- Stored OAuth registrations must be cleared and secrets rotated
Read next
Security