Threat
The MCP Python SDK’s OAuth Flaw Just Exposed the Real AI Agent Trust Problem
Publication date unknown · Discovered bonfy.ai
Page published
Publication date unknown · First observed: 9 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
The MCP Python SDK OAuth flaw sits in the reference code that underpins a large share of enterprise agent-to-tool connections, so a single credential-interception bug threatens every AI agent built on the vulnerable code path, not just one account.
A vulnerability disclosed September 28, 2026 in Anthropic's official Model Context Protocol (MCP) Python SDK, reported by Cycode, let a malicious MCP server redirect a connecting client to an attacker-controlled OAuth token endpoint, because the SDK's fallback discovery path trusted server-supplied configuration without verifying the token endpoint belonged to the expected authorization server. The flaw lived in the reference implementation imported by default by thousands of MCP clients; patches now validate issuers correctly, but many organizations lack an inventory of which MCP servers their agents connect to.