Critical OAuth Vulnerability in Anthropic’s MCP Python SDK Exposes User Accounts to Hijacking
A high-severity OAuth vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK (versions 1.9.1–2.1.1) could allow attackers to steal authentication credentials and take over user accounts. The flaw, discovered in the SDK’s OAuth discovery logic, enables malicious MCP servers to intercept sensitive OAuth data, including client secrets, authorization codes, and PKCE proof keys.
How the Attack Works
When an MCP client connects to a server requiring authentication, it must validate the legitimacy of the authorization server. However, in vulnerable SDK versions, an attacker-controlled MCP server can trigger a 404 response during server discovery, forcing the client into an unsafe fallback path. In this state, the SDK accepts OAuth configuration directly from the server without validating the issuer’s identity.
An attacker can then:
- Spoof a legitimate identity provider (e.g., Okta, Google, Microsoft Entra ID) while redirecting authentication to a malicious token endpoint.
- Trick users into authenticating via a real login page, then intercept the authorization code, client secret, and PKCE proof key.
- Redeem the stolen code at the legitimate provider, gaining access to the victim’s session with the same permissions.
Impact & Affected Components
The vulnerability affects HTTP-based MCP clients using:
- OAuthClientProvider
- ClientCredentialsOAuthProvider
- PrivateKeyJWTOAuthProvider
- Deprecated RFC7523OAuthClientProvider (1.x branch)
Exploiting this flaw could grant attackers persistent access to cloud services, internal APIs, databases, or deployment pipelines especially if refresh tokens or broad OAuth scopes are compromised. A stolen client secret may remain reusable until rotated.
Mitigation & Fixes
Anthropic has released patches in:
- MCP Python SDK v1.30.0 (1.x branch)
- MCP Python SDK v2.2.0 (2.x branch)
Organizations must:
- Upgrade immediately to the latest SDK version.
- Clear stored OAuth client registrations from older releases.
- Rotate client secrets and revoke tokens if an affected client connected to an untrusted MCP server.
- Explicitly configure
issuer=for ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, as upgrading alone does not secure these flows.
Unaffected deployments include MCP servers created with the SDK, local stdio clients, and clients using custom tokens or headers. The risk applies only to HTTP MCP clients connecting to untrusted servers while holding credentials for a legitimate OAuth provider.
Source: https://cyberpress.org/mcp-python-sdk-oauth-flaw/
Anthropic TPRM report: https://www.rankiteo.com/company/anthropicresearch
Microsoft Entra ID TPRM report: https://www.rankiteo.com/company/microsoft-security
"id": "antmic1790691866",
"linkid": "anthropicresearch, microsoft-security",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of MCP Python SDK '
'versions 1.9.1–2.1.1',
'industry': 'Artificial Intelligence / Software '
'Development',
'name': 'Anthropic',
'type': 'Company'}],
'attack_vector': 'Malicious MCP Server',
'customer_advisories': 'Users of affected SDK versions should upgrade and '
'rotate credentials',
'data_breach': {'data_exfiltration': 'Possible via malicious token endpoint',
'sensitivity_of_data': 'High (authentication credentials '
'enabling account takeover)',
'type_of_data_compromised': 'OAuth credentials (client '
'secrets, authorization codes, '
'PKCE proof keys)'},
'description': 'A high-severity OAuth vulnerability in Anthropic’s Model '
'Context Protocol (MCP) Python SDK (versions 1.9.1–2.1.1) '
'could allow attackers to steal authentication credentials and '
'take over user accounts. The flaw, discovered in the SDK’s '
'OAuth discovery logic, enables malicious MCP servers to '
'intercept sensitive OAuth data, including client secrets, '
'authorization codes, and PKCE proof keys.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'account hijacking risk',
'data_compromised': 'OAuth credentials (client secrets, '
'authorization codes, PKCE proof keys)',
'identity_theft_risk': 'High (account takeover via stolen OAuth '
'credentials)',
'operational_impact': 'Persistent access to cloud services, '
'internal APIs, databases, or deployment '
'pipelines if refresh tokens or broad OAuth '
'scopes are compromised',
'systems_affected': 'HTTP-based MCP clients using '
'OAuthClientProvider, '
'ClientCredentialsOAuthProvider, '
'PrivateKeyJWTOAuthProvider, or deprecated '
'RFC7523OAuthClientProvider'},
'lessons_learned': 'Importance of validating OAuth issuer identities and '
'avoiding unsafe fallback paths in authentication flows',
'post_incident_analysis': {'corrective_actions': 'Patch SDK to enforce issuer '
'validation and remove '
'unsafe fallback paths',
'root_causes': 'Flaw in OAuth discovery logic '
'allowing unsafe fallback to '
'attacker-controlled configuration'},
'recommendations': ['Immediately upgrade to the latest SDK version',
'Rotate client secrets and revoke tokens if exposed to '
'untrusted servers',
'Explicitly configure OAuth issuer parameters to prevent '
'spoofing'],
'references': [{'source': 'Anthropic Security Advisory'}],
'response': {'containment_measures': 'Upgrade to patched SDK versions (1.30.0 '
'for 1.x branch, 2.2.0 for 2.x branch)',
'remediation_measures': ['Clear stored OAuth client '
'registrations from older releases',
'Rotate client secrets and revoke '
'tokens if an affected client connected '
'to an untrusted MCP server',
'Explicitly configure `issuer=` for '
'ClientCredentialsOAuthProvider and '
'PrivateKeyJWTOAuthProvider']},
'title': 'Critical OAuth Vulnerability in Anthropic’s MCP Python SDK Exposes '
'User Accounts to Hijacking',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'OAuth discovery logic flaw (unsafe fallback path '
'in SDK versions 1.9.1–2.1.1)'}