thehackernews.com web signal

MCP Python SDK OAuth Flaw Lets Rogue Servers Steal Credentials

TL;DR

  • SDK versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 are vulnerable; fixes ship in 1.30.0 and 2.2.0.
  • A malicious MCP server can steal the client secret, authorization code, and PKCE proof key by redirecting OAuth discovery.
  • The advisory rates the bug CVSS 7.5 for non-interactive providers and 6.5 for the interactive one; no CVE assigned yet.

"A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service," the SDK's maintainers said in a security advisory, reported by The Hacker News.

The flaw sits in how the SDK discovers where to authenticate. When an MCP client needs to log in, it asks the server it is connecting to where its login service, called the authorization server, can be found. On the affected versions (1.9.1 through 1.29.1 in the 1.x line, and 2.0.0 through 2.1.1 in the 2.x line) the SDK did not always check that answer. A malicious server "could point it at a login service of the attacker's choosing, either by naming the attacker's own server or by serving login details that name the user's real service while sending the credentials elsewhere."

Three things leak: the client secret, the authorization code, and the PKCE proof key. Cycode, the security firm that reported the flaw, demonstrated the full exchange in a test and says the resulting token "carries whatever permissions the app was granted." The stolen client secret stays valid until manually rotated.

The advisory rates the bug CVSS 7.5 for non-interactive providers and 6.5 for the interactive one that requires user approval. Fixes ship in 1.30.0 and 2.2.0. No CVE has been assigned and no active exploitation has been reported.

Upgrading alone is not enough for two providers. If you use ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider, the advisory says "upgrading changes nothing until you also pass issuer=" to name the login service those credentials belong to.