#9
The Hacker News
general
September 29, 2026 at 06:08 UTC
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
By [email protected] (The Hacker News)
AI Summary
A vulnerability in the official MCP Python SDK allowed malicious MCP servers to intercept OAuth credentials — including client secrets, authorization codes, and PKCE proof keys — by redirecting token exchange requests to an attacker-controlled endpoint. The flaw was patched in MCP Python SDK version 1.30.0 and later, but any application built on earlier versions that connects to untrusted MCP servers may have been exposed. Given the rapid adoption of MCP-based AI tooling in enterprise environments, developers should audit dependencies and upgrade immediately.
Relevance score: 75.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →