Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
MCP Python SDK Vulnerability Risks OAuth Credential Theft

MCP Python SDK Vulnerability Risks OAuth Credential Theft

Posted on September 29, 2026 By CWS

A recent security advisory reveals a significant flaw in the official Model Context Protocol (MCP) Python SDK, potentially allowing malicious servers to capture OAuth credentials. This vulnerability could lead to unauthorized access to services, emphasizing the need for immediate updates to the latest SDK versions, specifically 1.30.0 and 2.2.0.

Understanding the MCP SDK Vulnerability

The MCP Python SDK, integral for establishing connections between artificial intelligence applications and external tools, was found to have a critical flaw. According to the SDK maintainers, a rogue MCP server could manipulate the SDK into sending OAuth credentials, including the client secret, authorization code, and PKCE proof key, to a server controlled by an attacker.

Once these credentials are intercepted, attackers can generate valid access tokens from legitimate login services. This exposes applications to significant security risks, as the tokens could carry extensive permissions granted to the app. Cycode, the security firm that identified the flaw, successfully demonstrated this vulnerability, highlighting its potential impact.

Affected Versions and Severity Scores

The vulnerability affects versions 1.9.1 through 1.29.1 of the 1.x line and 2.0.0 through 2.1.1 of the 2.x line. The issue has been rated with a high severity score of 7.5 for non-interactive providers, which do not require user intervention, and 6.5 for interactive providers, where user authentication is involved. As of September 29, no CVE identifier had been assigned to this vulnerability.

The flaw arises when an MCP client queries the server for its login service location. A compromised server can redirect the client to a malicious login service, capturing sensitive credentials. This issue is exacerbated for machine-to-machine interactions that bypass user confirmation.

Steps for Mitigation and Resolution

To mitigate this vulnerability, users should upgrade to versions 1.30.0 or 2.2.0. In these updates, the SDK verifies expected login services before processing any credentials. However, users of ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider must also specify the issuer of their credentials to ensure security. For deprecated providers without this option, transitioning to supported versions is recommended.

After upgrading, it is crucial to clear any saved OAuth client registrations, as older registrations are not linked to specific login services. Additionally, if there is any suspicion of prior exposure, rotating client secrets and revoking tokens is advised. The advisory emphasizes the importance of connecting only to trusted MCP servers.

The release notes, issued on September 7, initially documented these changes under behavior modifications rather than as a security fix. The security advisory was later released on September 28, alongside Cycode’s detailed analysis. While no active exploitation has been reported, the disclosure credits multiple researchers, including those from Cycode.

Looking Ahead

This incident underscores the importance of regular software updates and vigilant security practices. Organizations using the MCP Python SDK should implement the recommended updates promptly to safeguard their systems against potential threats. Continuous monitoring and adherence to security advisories remain crucial in mitigating risks associated with software vulnerabilities.

The Hacker News Tags:access token, Authorization, client secret, Cybersecurity, Cycode, identity security, MCP, OAuth, PKCE, Python SDK, SDK update, security advisory, security fix, software update, software vulnerability

Post navigation

Previous Post: Security Alert: Malicious VPN Extensions Compromise Chrome
Next Post: Apple Fixes Zero-Day Vulnerability Uncovered by Meta

Related Posts

Unveiling Eight Attack Vectors in AWS Bedrock Unveiling Eight Attack Vectors in AWS Bedrock The Hacker News
AI Revolutionizes Cybersecurity: The Rise of Vibe Hacking AI Revolutionizes Cybersecurity: The Rise of Vibe Hacking The Hacker News
North Korean Hackers Use Fake Microsoft Alerts to Spread NarwhalRAT North Korean Hackers Use Fake Microsoft Alerts to Spread NarwhalRAT The Hacker News
U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme U.S. Sanctions North Korean Andariel Hacker Behind Fraudulent IT Worker Scheme The Hacker News
XRING Flaw in XQUIC Poses Risk to HTTP/3 Servers XRING Flaw in XQUIC Poses Risk to HTTP/3 Servers The Hacker News
GodDamn Ransomware Employs PoisonX to Bypass Security GodDamn Ransomware Employs PoisonX to Bypass Security The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Halts GPT-6.1 Astra Due to Safety Concerns
  • Pentagon Breach Exposes Sensitive Data of Millions
  • Apple Fixes Zero-Day Vulnerability Uncovered by Meta
  • MCP Python SDK Vulnerability Risks OAuth Credential Theft
  • Security Alert: Malicious VPN Extensions Compromise Chrome

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Halts GPT-6.1 Astra Due to Safety Concerns
  • Pentagon Breach Exposes Sensitive Data of Millions
  • Apple Fixes Zero-Day Vulnerability Uncovered by Meta
  • MCP Python SDK Vulnerability Risks OAuth Credential Theft
  • Security Alert: Malicious VPN Extensions Compromise Chrome

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark