HomeSecurityMCP Python SDK: Stealing OAuth credentials from malicious servers

MCP Python SDK: Stealing OAuth credentials from malicious servers

The MCP Python SDK — the official development kit for the Model Context Protocol — has been found to have a serious vulnerability that allows malicious servers to intercept the OAuth credentials of applications that use it. The discovery was made by cybersecurity firm Cycode, which published its findings on September 28, 2026, while the SDK maintainers issued a corresponding security advisory on the same day. The vulnerability affects applications that use the SDK as an MCP client over HTTP and can connect to servers that they do not fully control.

See also: JeetBot: Malicious Twitch extension leaked OAuth tokens of 31,000 users

MCP Python SDK vulnerability theft of OAuth credentials malicious servers

The Model Context Protocol (MCP) is an open standard designed to connect AI applications to external tools and data. The official Python SDK serves as the primary library for building MCP servers and clients. Its widespread adoption in the AI ​​ecosystem makes the vulnerability particularly concerning, as it could potentially impact a large number of applications that rely on it for authentication with external services.

The affected versions of the SDK send the client secret, authorization code , and PKCE proof key to a token endpoint controlled by the attacker. With this data, the malicious user can request a valid access token from the real login service, gaining access with the same privileges as the application. The client secret is long-lived and remains valid until it is changed.

How the MCP Python SDK vulnerability is exploited

The attack works by exploiting a fundamental authentication flaw. When an MCP client needs to connect, it asks the server it is connecting to for the location of its login service, known as an authorization server. In the affected versions, the SDK did not consistently verify this response. A malicious server could redirect the client to a login service of the attacker's choosing — either by directly naming the attacker's server, or by providing login credentials that appear to point to the user's real service, while in fact sending the credentials elsewhere.

The client then sends the client secret, authorization code , and PKCE proof key to the attacker instead of the legitimate service. The PKCE proof key is a one-time value designed to prevent reuse of a stolen authorization code — giving it to the attacker completely undermines this protection. Cycode demonstrated this exchange in a test environment, confirming that the resulting token carries all the permissions granted to the application.

The vulnerability is rated as high severity (7.5) for both providers that operate without human intervention. For the interactive provider, where a person must initiate the connection, it is rated 6.5 . It is worth noting that even in the case of the interactive provider, the page that the user approves is the genuine login page — nothing looks suspicious, making the attack particularly difficult to detect. No CVE number was assigned as of September 29, 2026 .

See also: ShinyHunters: Salesforce data theft via OAuth

MCP Python SDK - SecNews.gr

What applications are affected by the MCP Python SDK and how to protect yourself

An application is affected if it uses the MCP Python SDK as an MCP client over HTTP with one of the following OAuth providers: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated RFC7523OAuthClientProvider version 1.x. In addition, the application must be able to connect to a server that it does not fully control, while possessing credentials for a real connection service. MCP serversbuilt with the SDK, local (stdio) clients, and clients that attach their own tokens are not affected.

The fix is ​​included in versions 1.30.0 and 2.2.0. In the fixed versions, the client specifies which connection service it expects before retrieving any credentials and rejects any that specify a different one. However, the upgrade alone does not fully resolve the issue for two of the providers. If you are using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider, the advisory explicitly states that "the upgrade does not change anything until you also pass issuer=" to specify the connection service that these credentials belong to.

An additional issue concerns the visibility of the warning: in version 1.30.0, the warning for this is a standard deprecation warning, which Python hides by default, making it easy to overlook. The deprecated RFC7523OAuthClientProvider does not have an issuer=, so users will have to switch to one of the other two providers. This makes the recovery process more complex than a simple upgrade.

After upgrading, it is important to delete any stored OAuth client registrations once, as older ones are not associated with a connection service and remain that way. If a client may have already connected to an untrusted server, it is recommended to rotate the client secret and revoke the tokens in the connection service. For older versions, there is no other solution than to connect exclusively to trusted MCP servers.

The impact of the MCP Python SDK vulnerability on the AI ​​ecosystem

The discovery of this vulnerability highlights a broader security issue in the rapidly growing AI and MCP ecosystem. As more and more AI applications integrate external tools and services through protocols like MCP, the attack surface is expanding significantly. The trust that applications place in the servers they communicate with must be accompanied by strict verification mechanisms.

It is worth noting that the issuer checks were included in the release notes for versions 1.30.0 and 2.2.0 on September 7, 2026, listed as a behavior change rather than a security fix. This means that many developers may not have realized the severity of the change and have not taken the necessary measures. The advisory was issued on September 28, the same day that Cycode published its findings, giving users a clear picture of the risk.

See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CVE-2026-86950 Apple zero-day CoreGraphics Meta vulnerability

For organizations using applications based on the MCP Python SDK, immediate action is imperative. In addition to upgrading to versions 1.30.0 or 2.2.0, security teams should verify that their applications are using the affected OAuth providers, properly configure the issuer= where required, and perform a scan for suspicious connections to untrusted servers. Software supply chain security — especially for AI tools — is now a critical priority for any organization leveraging modern AI technologies.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Previous article
Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS