MCP Python SDK Flaw Risks OAuth Credential Theft in AI Applications
Share
A security flaw in the official Model Context Protocol (MCP) Python SDK can allow malicious servers to intercept OAuth credentials, potentially compromising the security of AI applications and their connected services.
The vulnerability, disclosed by security firm Cycode, enables an attacker-controlled MCP server to trick an application into handing over sensitive data, including client secrets, authorisation codes, and PKCE (Proof Key for Code Exchange) proof keys. With these credentials, an attacker can request valid access tokens from the legitimate login service, gaining the same permissions as the original application.
Technical Details of the Flaw
The Model Context Protocol (MCP) is an open standard designed to connect AI applications to external tools and datasets. When an MCP client needs to authenticate, it asks the connected server for the location of its authorisation server.
In affected versions of the Python SDK, the client does not always verify the legitimacy of this response. A malicious server can redirect the client to an attacker-controlled endpoint. In interactive scenarios, the user may see a genuine-looking login page, making the redirection difficult to detect. In machine-to-machine scenarios—where no human is present to approve the sign-in—the risk is significantly higher.
The flaw has been assigned a high severity score of 7.5 for machine-to-machine providers and 6.5 for interactive providers. As of late September 2026, there have been no reports of this vulnerability being exploited in the wild.
Affected Versions and Mitigation
The vulnerability affects applications using the SDK as an MCP client over HTTP with the following OAuth providers:
- OAuthClientProvider
- ClientCredentialsOAuthProvider
- PrivateKeyJWTOAuthProvider
- RFC7523OAuthClientProvider (deprecated)
To address the issue, developers should upgrade to version 1.30.0 for the 1.x line or version 2.2.0 for the 2.x line. However, a simple upgrade may not be sufficient for all configurations.
For applications using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider, the SDK now requires the issuer= parameter to be passed explicitly to name the intended login service. Without this parameter, the SDK may still follow instructions from an untrusted MCP server. Furthermore, developers using the deprecated RFC7523 provider should migrate to one of the supported alternatives.
If an application is suspected of having connected to an untrusted server, security teams should immediately rotate the client secret and revoke all existing tokens at the relevant login service. Additionally, clearing any stored OAuth client registrations is recommended following the upgrade.




Leave a Reply