Threat · curated 29 Sep 2026
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
First reported thehackernews.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
The MCP Python SDK underpins many AI applications connecting agents to external tools, so a credential-theft flaw in it exposes OAuth-authenticated services to takeover by any malicious MCP server an application connects to.
The official MCP Python SDK contains a flaw (GHSA-qx49-fqc8-xw99) that lets a malicious MCP server trick a client application into sending its OAuth client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, enabling account takeover. Cycode, which reported the flaw, demonstrated the full credential-exchange attack; fixes are available in versions 1.30.0 and 2.2.0.