Critical OAuth Credential Theft Flaw Discovered in MCP Python SDK
A high-severity vulnerability in the official Model Context Protocol (MCP) Python SDK could allow attackers to steal OAuth credentials from applications using affected versions. The flaw, disclosed in a September 28 security advisory, enables malicious MCP servers to redirect authentication requests to an attacker-controlled endpoint, intercepting sensitive data including client secrets, authorization codes, and PKCE proof keys.
How the Attack Works
When an MCP client initiates login, it queries the server for the location of the authorization server. In vulnerable versions (1.9.1–1.29.1 and 2.0.0–2.1.1), the SDK failed to validate this response, allowing attackers to misdirect the client to a fake login service. The stolen credentials could then be used to obtain a valid access token from the legitimate service, granting attackers the same permissions as the compromised application.
For interactive OAuth providers, users must still approve the login, but the process appears legitimate since the genuine login page is displayed. Machine-to-machine providers (e.g., ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider) are more severely impacted, as they require no user interaction.
Impact & Severity
- CVSS Score: 7.5 (High) for non-interactive providers, 6.5 (Medium) for interactive ones.
- No CVE assigned as of September 29.
- Long-lived client secrets remain exploitable until rotated.
- No known attacks have been reported, but the flaw was demonstrated in testing by Cycode, the security firm that discovered it.
Affected Systems & Fixes
Applications using the SDK as an MCP client over HTTP with the following OAuth providers are vulnerable:
OAuthClientProviderClientCredentialsOAuthProviderPrivateKeyJWTOAuthProvider- (Deprecated)
RFC7523OAuthClientProvider
Fixed versions:
- 1.x line: Upgrade to 1.30.0
- 2.x line: Upgrade to 2.2.0
For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, the fix requires explicitly setting the issuer= parameter to bind credentials to a trusted login service. The deprecated RFC7523OAuthClientProvider lacks this option and should be replaced.
Mitigation Steps
- Upgrade immediately to patched versions.
- Rotate client secrets and revoke tokens if untrusted connections may have occurred.
- Clear stored OAuth registrations post-upgrade, as older entries remain unbound to a specific issuer.
- No workaround exists for unpatched versions other than restricting connections to trusted MCP servers.
The fixes were released on September 7, with the advisory following on September 28, the same day Cycode published its findings. The disclosure credits eight researchers, including Cycode’s team.
Source: https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
Model Context Protocol cybersecurity rating report: https://www.rankiteo.com/company/modelcontextprotocol
"id": "MOD1790677673",
"linkid": "modelcontextprotocol",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology, Software Development',
'name': 'Applications using MCP Python SDK',
'type': 'Software Development Kits (SDKs)'}],
'attack_vector': 'Malicious MCP server redirecting OAuth authentication '
'requests',
'data_breach': {'data_exfiltration': 'Potential interception via '
'attacker-controlled endpoint',
'personally_identifiable_information': 'Potential (if '
'accessed via stolen '
'tokens)',
'sensitivity_of_data': 'High (credentials could grant '
'unauthorized access to application '
'permissions)',
'type_of_data_compromised': 'OAuth credentials (client '
'secrets, authorization codes, '
'PKCE proof keys, access tokens)'},
'date_detected': '2023-09-07',
'date_publicly_disclosed': '2023-09-28',
'date_resolved': '2023-09-07',
'description': 'A high-severity vulnerability in the official Model Context '
'Protocol (MCP) Python SDK could allow attackers to steal '
'OAuth credentials from applications using affected versions. '
'The flaw enables malicious MCP servers to redirect '
'authentication requests to an attacker-controlled endpoint, '
'intercepting sensitive data including client secrets, '
'authorization codes, and PKCE proof keys.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'credential theft vulnerability',
'data_compromised': 'OAuth credentials (client secrets, '
'authorization codes, PKCE proof keys, access '
'tokens)',
'identity_theft_risk': 'High (if personally identifiable '
'information is accessed via stolen tokens)',
'operational_impact': 'Potential unauthorized access to '
'application permissions via stolen access '
'tokens',
'systems_affected': 'Applications using MCP Python SDK as an MCP '
'client over HTTP with vulnerable OAuth '
'providers'},
'investigation_status': 'Completed (vulnerability patched and disclosed)',
'lessons_learned': 'Importance of validating server responses in OAuth flows, '
'need for explicit issuer binding in credentials, risks of '
'long-lived client secrets',
'post_incident_analysis': {'corrective_actions': 'Added validation for '
'authorization server '
'responses, introduced '
'explicit `issuer=` '
'parameter binding for '
'credentials',
'root_causes': 'Lack of validation for '
'authorization server response in '
'MCP Python SDK, allowing '
'redirection to attacker-controlled '
'endpoints'},
'recommendations': ['Upgrade to patched versions (1.30.0 or 2.2.0) '
'immediately',
'Rotate client secrets and revoke tokens if untrusted '
'connections may have occurred',
'Clear stored OAuth registrations post-upgrade',
'Explicitly set `issuer=` parameter for vulnerable OAuth '
'providers',
'Replace deprecated `RFC7523OAuthClientProvider`',
'Restrict connections to trusted MCP servers if unable to '
'upgrade'],
'references': [{'date_accessed': '2023-09-28',
'source': 'Cycode Security Advisory'}],
'response': {'communication_strategy': 'Security advisory published on '
'September 28, 2023',
'containment_measures': 'Upgrade to patched versions (1.30.0 or '
'2.2.0), rotate client secrets, revoke '
'tokens, clear stored OAuth '
'registrations',
'recovery_measures': 'Rotate credentials and revoke tokens '
'post-upgrade',
'remediation_measures': 'Explicitly set `issuer=` parameter for '
'vulnerable OAuth providers, replace '
'deprecated `RFC7523OAuthClientProvider`',
'third_party_assistance': 'Cycode (security firm that discovered '
'the flaw)'},
'stakeholder_advisories': 'Security advisory published on September 28, 2023, '
'detailing the vulnerability and mitigation steps',
'title': 'Critical OAuth Credential Theft Flaw Discovered in MCP Python SDK',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'Lack of validation for authorization server '
'response in MCP Python SDK (versions 1.9.1–1.29.1 '
'and 2.0.0–2.1.1)'}