importantSYS.SOURCE: The Hacker News• 2026-09-29T11:38:25+05:30
MCP Python SDK Vulnerability Enables OAuth Credential Theft via Malicious Servers
A critical vulnerability in the MCP Python SDK allows malicious servers to steal OAuth credentials by intercepting client secrets and authorization codes. The issue is resolved in versions 1.30.0 and 2.2.0, with recommendations to upgrade and revoke compromised tokens.
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.
Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
*** END OF TRANSMISSION ***