Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Security

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

The Hacker News · Sep 29, 2026

Back to News
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Security September 29, 2026

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.