Threat

MCP Login Flaw Exposes OAuth Trust Check Gap

Page published

Earliest dated coverage: 1 Oct 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 1 Oct 2026

Coverage timeline

discovered cycode.com primary 1 Oct 2026securitypointbreak.com

Single-source incident — one report is available.

Why it matters

The MCP Python SDK OAuth flaw enables full account takeover across the most widely used AI connectors, showing that official AI-to-app plumbing can leak the very credentials users believe they are safely approving.

Cycode researcher Yuval Elbar discovered a now-patched flaw in the official MCP Python SDK that let malicious or tampered MCP servers hijack the OAuth sign-in flow used to connect AI assistants (ChatGPT, Claude, Cursor, Gemini, Microsoft Copilot) to apps like Slack, GitHub and Google Drive. Victims sign in through a genuine Google, Okta or Microsoft page, but the authorization codes that complete the login are diverted to the attacker, granting them the access the victim just approved; attackers can also typosquat connector names to lure victims. The issue is tracked in a GitHub security advisory (GHSA-qx49-fqc8-xw99).