Critical Flaw in MCP Python SDK Exposes OAuth Credentials to Attackers
Article Content
- •Malicious MCP servers can intercept OAuth credentials due to a validation flaw.
- •Versions 1.9.1 to 2.1.1 are affected; patches 1.30.0 and 2.2.0 are available.
- •Attackers can exploit the flaw without user interaction in unattended environments.
A vulnerability in the official MCP Python SDK allows malicious servers to intercept OAuth credentials from clients. The flaw exists in versions 1.9.1 through 2.1.1, where the SDK fails to validate the authorization server metadata issuer. Attackers can exploit this by directing clients to a token endpoint of their choice, capturing sensitive information such as client secrets and authorization codes. The flaw affects applications using the SDK as an MCP client over HTTP with specific OAuth providers. Affected versions have been rated with a high severity score of 7.5 for unattended providers and 6.5 for interactive providers. The maintainers have released patched versions 1.30.0 and 2.2.0 to address this issue. Users are advised to upgrade immediately, and additional measures are required for certain OAuth providers. No CVE has been assigned as of September 29, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…