Threat

The MCP Python SDK’s OAuth Flaw Just Exposed the Real AI Agent Trust Problem

Page published

Publication date unknown · First observed: 9 Oct 2026

Coverage timeline

9 Oct 2026bonfy.aiobserved

Single-source analysis — one report is available.

Why it matters

The MCP Python SDK OAuth flaw sits in the reference code that underpins a large share of enterprise agent-to-tool connections, so a single credential-interception bug threatens every AI agent built on the vulnerable code path, not just one account.

A vulnerability disclosed September 28, 2026 in Anthropic's official Model Context Protocol (MCP) Python SDK, reported by Cycode, let a malicious MCP server redirect a connecting client to an attacker-controlled OAuth token endpoint, because the SDK's fallback discovery path trusted server-supplied configuration without verifying the token endpoint belonged to the expected authorization server. The flaw lived in the reference implementation imported by default by thousands of MCP clients; patches now validate issuers correctly, but many organizations lack an inventory of which MCP servers their agents connect to.