Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Overview
A vulnerability in the official MCP Python SDK allows attackers to create malicious servers that can trick applications into revealing OAuth credentials. This issue affects versions prior to 1.30.0, where sensitive information like the client secret, authorization code, and PKCE proof key could be sent to an attacker-controlled token endpoint. The SDK's maintainers have issued a security advisory regarding this flaw, emphasizing the risk it poses to applications relying on OAuth for authentication. Users of the affected SDK should update to version 1.30.0 or later to secure their applications against potential credential theft. This incident underscores the need for developers to stay vigilant about the libraries they use and the security implications they carry.
Key Takeaways
- Affected Systems: MCP Python SDK versions prior to 1.30.0
- Action Required: Update to MCP Python SDK version 1.
- Timeline: Newly disclosed
Original Article Summary
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
Impact
MCP Python SDK versions prior to 1.30.0
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Update to MCP Python SDK version 1.30.0 or later.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Update.