A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory.
Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and 2.2.0.
The Model Context Protocol (MCP) is an open standard for connecting AI applications to outside tools and data, and this package is its official Python SDK for building MCP servers and clients.
With the stolen credentials, the attacker can request a valid access token from the real login service. Cycode, the security firm that reported the flaw, demonstrated that full exchange in a test and says the resulting token carries whatever permissions the app was granted. The client secret is long-lived, so it keeps working until it is changed.
The flaw is rated high (7.5) for the two providers that run without a person present. Scored for the interactive provider, where someone has to start the sign-in, it is 6.5. No CVE had been assigned as of September 29.
How a server steals the credentials
When an MCP client needs to log in, it asks the server it is connecting to where its login service, called the authorization server, can be found. On the affected versions, the SDK did not always check that answer. A malicious server could point it at a login service of the attacker’s choosing, either by naming the attacker’s own server or by serving login details that name the user’s real service while sending the credentials elsewhere.


Leave a Reply