Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Malicious MCP servers could steal OAuth client secrets and PKCE keys from apps using the official Python SDK; fixed in 1.30.0 and 2.2.0.
The official MCP Python SDK failed to validate authorization-server metadata, letting a malicious MCP server redirect OAuth flows and capture the client secret, authorization code, and PKCE proof key. Cycode, which reported the flaw, demonstrated a full token exchange granting attacker access with the app's granted permissions; the long-lived client secret keeps working until rotated. The flaw is rated 7.5 for the two non-interactive providers and 6.5 for the interactive provider, with no CVE assigned as of September 29. Fixes shipped in 1.30.0 (1.x) and 2.2.0 (2.x), but ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider users must also pass issuer= and rotate secrets if untrusted servers were ever contacted; no attacks have been reported.