Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Security advisory warns of credential exfiltration risk in affected SDK versions

Key Takeaways
- A vulnerability in the official MCP Python SDK could allow malicious servers to steal OAuth credentials.
- Affected versions transmit client secrets, authorization codes, and PKCE proof keys to token endpoints.
- The fix is available in version 1.30.0 and later.
- Users should update the SDK to the latest version to protect against credential theft.
Quick answers
- What happened?
- The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.
- Which products are affected?
- MCP Python SDK
- What should defenders do?
- Update the MCP Python SDK to version 1.30.0 or later. Apply the security fix released by the SDK maintainers to prevent unauthorized access to OAuth credentials.
A security advisory issued by the MCP Python SDK maintainers reveals a flaw that could allow a malicious server to steal OAuth credentials from applications using the SDK. The vulnerability stems from the way affected versions transmit sensitive authentication data. Specifically, the SDK sends the client secret, the authorization code, and the PKCE proof key to a token endpoint. A malicious server controlling the token endpoint could potentially intercept or exploit this data flow. The maintainers have released a fix in version 1.30.0 and subsequent releases to address the issue. Users of the SDK are advised to update to the latest patched version to mitigate the risk of credential exfiltration.
Security Details
Affected versions of the MCP Python SDK sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. This mishandling of sensitive OAuth data could allow a malicious server to intercept credentials.
Affected products
MCP Python SDK
Mitigation
Update the MCP Python SDK to version 1.30.0 or later. Apply the security fix released by the SDK maintainers to prevent unauthorized access to OAuth credentials.
Sources
The Hacker News
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Sep 29, 2026 · 06:08
Original link
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.




