The Hacker News reports that a flaw in the official MCP Python SDK let a malicious MCP server misdirect OAuth discovery so that affected clients could send a client secret, authorization code, and PKCE proof key to an attacker-controlled endpoint. Versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 are affected, fixes ship in 1.30.0 and 2.2.0, and operators of the client-credentials and private-key JWT providers must also configure an explicit issuer and rotate any exposed credentials; the report notes no known exploitation and no assigned CVE at the time of writing.
Official MCP Python SDK flaw can let malicious servers steal OAuth credentials
The Hacker News reports that a flaw in the official MCP Python SDK let a malicious MCP server misdirect OAuth discovery so that affected clients could send a client secret, authorization code, and PKCE proof key to an attacker-controlled endpoint. Versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 are affected, fixes ship in 1.30.0 and 2.2.0, and operators of the client-credentials and private-key JWT providers must also configure an explicit issuer and rotate any exposed credentials; the report notes no known exploitation and no assigned CVE at the time of writing.
Source: Thehackernews