Skip to content
Critical Flaw in MCP Python SDK Exposes OAuth Credentials to Attackers

Critical Flaw in MCP Python SDK Exposes OAuth Credentials to Attackers

First seen 29 Sep 2026, 07:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 08:10 UTC
  • •Malicious MCP servers can intercept OAuth credentials due to a validation flaw.
  • •Versions 1.9.1 to 2.1.1 are affected; patches 1.30.0 and 2.2.0 are available.
  • •Attackers can exploit the flaw without user interaction in unattended environments.

A vulnerability in the official MCP Python SDK allows malicious servers to intercept OAuth credentials from clients. The flaw exists in versions 1.9.1 through 2.1.1, where the SDK fails to validate the authorization server metadata issuer. Attackers can exploit this by directing clients to a token endpoint of their choice, capturing sensitive information such as client secrets and authorization codes. The flaw affects applications using the SDK as an MCP client over HTTP with specific OAuth providers. Affected versions have been rated with a high severity score of 7.5 for unattended providers and 6.5 for interactive providers. The maintainers have released patched versions 1.30.0 and 2.2.0 to address this issue. Users are advised to upgrade immediately, and additional measures are required for certain OAuth providers. No CVE has been assigned as of September 29, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-29
Vulnerability disclosed
Security advisory published detailing the flaw in the MCP Python SDK affecting OAuth credential handling.
Feeds.Feedburner
2026-09-29
Patch released
Versions 1.30.0 and 2.2.0 released to fix the vulnerability in the MCP Python SDK.
github.com

More articles in this cluster (3)