MCP Python SDK OAuth flaw lets rogue servers steal your tokens
A malicious server can grab your client secret, auth code and PKCE key. Upgrade to 1.30.0 / 2.2.0 — and for two providers, that alone won't fix it.

Copy markdown
What a rogue MCP server can steal
During OAuth discovery the SDK never checked where the login server actually lived, so a malicious MCP server can point you at its own fake authorizer and intercept your client secret, authorization code and PKCE proof key — enough to mint a real token with your permissions. It hits mcp 1.9.1–1.29.1 and 2.0.0–2.1.1, rated CVSS 7.5.
Upgrading alone won't save two providers
Bump to 1.30.0 (1.x) or 2.2.0 (2.x) today. But ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider stay exposed until you also pass issuer= to pin the real auth server. If you've ever connected to an untrusted server, clear stored OAuth registrations and rotate your client secrets too.
Why this one stings for agent builders
MCP's whole pitch is wiring into servers you didn't write — which is exactly the attack surface here. Cycode and seven other researchers reported it, and the blast radius is any Python agent that ever spoke OAuth to a third-party server. Audit your connection list before your next run.