Threat · curated 29 Sep 2026

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Coverage timeline

29 Sep 2026thehackernews.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

The MCP Python SDK underpins many AI applications connecting agents to external tools, so a credential-theft flaw in it exposes OAuth-authenticated services to takeover by any malicious MCP server an application connects to.

The official MCP Python SDK contains a flaw (GHSA-qx49-fqc8-xw99) that lets a malicious MCP server trick a client application into sending its OAuth client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, enabling account takeover. Cycode, which reported the flaw, demonstrated the full credential-exchange attack; fixes are available in versions 1.30.0 and 2.2.0.