Official MCP Python SDK Hands OAuth Secrets to Malicious Servers
Key Takeaways
- The official MCP Python SDK did not validate the OAuth authorization server a client was sent to.
- A malicious MCP server could redirect token exchanges to an attacker-controlled endpoint.
- Exposed materials included client secrets, authorization codes, and PKCE verifiers.
- Versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 were affected; fixes shipped September 7.
- No exploitation has been reported.
A Trusted SDK Trusted the Wrong Login Server
The Model Context Protocol project published a security advisory for its official Python SDK after researchers found that a malicious MCP server could steal OAuth credentials from connecting clients. As The Hacker News reported, the flaw affects the reference SDK many MCP clients are built on.
What We Know
The issue affected MCP Python SDK versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, and was fixed in versions 1.30.0 and 2.2.0, released September 7, 2026. The advisory was published September 28 without a CVE. Severity was rated 7.5 for non-interactive OAuth providers and 6.5 for interactive ones.
Researchers at Cycode and eight other reporters were credited. Affected deployments are MCP clients that use HTTP transport with the SDK's built-in OAuth providers and connect to untrusted servers. MCP servers, stdio clients, and applications that manage their own tokens were not affected. No exploitation has been reported.
What Could Happen
When an MCP client connects to a server that requires OAuth, it discovers which authorization server to use. The vulnerable SDK did not verify that endpoint. A malicious or compromised MCP server could point the client at an attacker-controlled token endpoint, either by impersonating the legitimate login service or by directing traffic elsewhere.
The client would then send its client secret, authorization code, and PKCE verifier to the attacker. With those, the attacker could request valid access tokens from the real service, inheriting every permission granted to the client. Because client secrets are long-lived, the exposure could outlast a single session.
Why It Matters
MCP is quickly becoming the standard way agents connect to enterprise tools, and the official SDK is a foundational building block. A flaw there propagates to every application built on affected versions, often without developers knowing.
The case also shows how much trust MCP clients place in servers. Connecting to an unknown MCP server is not just a data-exposure risk; it can hand over credentials for unrelated systems. Organizations should upgrade, set explicit issuers, clear stored registrations, and rotate secrets if exposure is possible.
PointGuard AI Perspective
MCP needs a security boundary between agents and the servers they connect to. The PointGuard AI MCP Security Gateway centralizes MCP connections, enforces which servers and tools each agent may use, and keeps credentials out of individual clients so a malicious server cannot harvest them. PointGuard AI also inventories MCP servers and SDK versions across the environment to flag vulnerable components quickly.
Our blog MCP Breaks Zero Trust. Here's How to Fix It. explains why every MCP connection should be verified rather than assumed safe. As MCP adoption grows, trustworthy agent ecosystems depend on treating every server as untrusted until proven otherwise.
Incident Scorecard Details
Total AISSI Score: 6.4/10
Criticality: 7, OAuth client secrets and tokens can unlock the connected services an MCP client is authorized to use. AISSI weighting: 25%
Propagation: 8, The flaw sat in the official SDK used across many MCP clients and agent applications. AISSI weighting: 20%
Exploitability: 4, The attack was demonstrated by researchers, with no exploitation reported. AISSI weighting: 15%
Supply Chain: 8, The risk comes from a shared open-source SDK and untrusted third-party MCP servers. AISSI weighting: 15%
Business Impact: 5, Patched quickly with no confirmed harm, though credential exposure could be long-lived. AISSI weighting: 25%
Sources
Third-Party Sources
- MCP Python SDK Security Advisory GHSA-qx49-fqc8-xw99
- The Hacker News: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
