MCP Python SDK OAuth flaw lets rogue servers steal your tokens

A malicious server can grab your client secret, auth code and PKCE key. Upgrade to 1.30.0 / 2.2.0 — and for two providers, that alone won't fix it.

Nowline SEP 30 3:00 AM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • What a rogue MCP server can steal

    During OAuth discovery the SDK never checked where the login server actually lived, so a malicious MCP server can point you at its own fake authorizer and intercept your client secret, authorization code and PKCE proof key — enough to mint a real token with your permissions. It hits mcp 1.9.1–1.29.1 and 2.0.0–2.1.1, rated CVSS 7.5.

  • Upgrading alone won't save two providers

    Bump to 1.30.0 (1.x) or 2.2.0 (2.x) today. But ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider stay exposed until you also pass issuer= to pin the real auth server. If you've ever connected to an untrusted server, clear stored OAuth registrations and rotate your client secrets too.

  • Why this one stings for agent builders

    MCP's whole pitch is wiring into servers you didn't write — which is exactly the attack surface here. Cycode and seven other researchers reported it, and the blast radius is any Python agent that ever spoke OAuth to a third-party server. Audit your connection list before your next run.