chiprook
← Security
SecurityOctober 4, 2026, 07:13

MCP SDK OAuth fix audit: patching alone leaves the hole open

On September 28 the MCP Python SDK shipped a fix for credential-theft bug GHSA-qx49-fqc8-xw99 (CVSS 7.5): a malicious MCP server could steer OAuth discovery and capture the client_secret, authorization code and PKCE code_verifier. Upgrading to 1.30.0 or 2.2.0 is not enough unless ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider are constructed with an explicit issuer.

MCP SDK OAuth fix audit: patching alone leaves the hole open
#MCP#Python
Read next
Security

MCP Python SDK OAuth flaw lets malicious servers steal client secrets

Security

2,967 MCP servers advertise OAuth; only 8% meet July spec

Software

MCP ships biggest update yet: stateless architecture and hardened OAuth

Software

Codex CLI 0.158: approval for elevated commands and MCP OAuth client secrets