MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
A critical vulnerability in the official MCP Python SDK could allow malicious servers to steal OAuth credentials. Developers using affected versions should upgrade immediately.
TL;DR
- The MCP Python SDK had a flaw allowing malicious servers to steal OAuth credentials.
- Affected versions improperly sent sensitive data to attacker-controlled endpoints.
- Versions 1.30.0 and later include a fix for this vulnerability.
- Applications using the SDK should be updated to prevent credential theft.
- Developers are advised to review their authentication flows for potential exposure.
A serious security vulnerability has been identified in the official MCP Python SDK that could result in the theft of OAuth credentials. According to the SDK maintainers, a malicious MCP server could manipulate applications into sending sensitive authentication data to attacker-controlled endpoints.
The issue affects how the SDK handles OAuth flows, specifically exposing the client secret, authorization code, and PKCE proof key during token requests. This type of flaw can lead to unauthorized access to protected services and resources, making it critical for development teams to take immediate action.
Vulnerability Details
- Affected SDK versions transmitted OAuth client secrets and PKCE data to endpoints controlled by attackers.
- The flaw enabled malicious servers to impersonate legitimate services and collect authentication tokens.
- Sensitive data included the authorization code, client secret, and PKCE verifier—key components in secure OAuth flows.
Impact and Mitigation
- Applications using vulnerable SDK versions are at risk of credential theft and unauthorized API access.
- Developers should immediately upgrade to MCP Python SDK version 1.30.0 or newer.
- Organizations should audit their authentication implementations for any signs of compromise.
- Reviewing logs for unexpected outbound requests to unknown token endpoints is recommended.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.