Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in MCP Python SDK Exposes AI Accounts

Critical Flaw in MCP Python SDK Exposes AI Accounts

Posted on September 30, 2026 By CWS

A significant security vulnerability in the Model Context Protocol (MCP) Python SDK has been identified, potentially allowing malicious actors to hijack AI agent accounts by exploiting OAuth authentication weaknesses.

Understanding the OAuth Flaw

This flaw impacts MCP clients using OAuth to connect to identity providers such as Google, Okta, or Microsoft Entra ID, especially when these clients unknowingly interact with unverified servers. The MCP protocol is designed to facilitate AI tools in connecting with external data sources, but this flaw exposes clients to potential security breaches.

The problem arises from the SDK’s over-reliance on data from MCP servers, which can be manipulated by attackers to redirect OAuth exchanges to their own controlled infrastructure, bypassing legitimate security measures.

Technical Details of the Exploit

The exploitation process starts when a rogue MCP server responds to authorization-server discovery requests with a 404 error, leading the SDK to follow a fallback path. This path accepts OAuth configurations directly from the MCP server, without verifying the legitimacy of the OAuth issuer.

Attackers can then present a legitimate login interface from trusted providers while directing the OAuth token endpoint to a malicious server. This deception allows attackers to gain access tokens by sending authorization codes and other credentials to their endpoint.

Cycode has highlighted that this flaw compromises credential-binding protections, allowing attackers to impersonate legitimate servers and misuse stored credentials.

Impacted Versions and Mitigation

Several versions of the MCP Python SDK are affected, including 1.9.1 to 1.29.1 in the 1.x series and 2.0.0 to 2.1.1 in the 2.x series. Affected OAuth providers include OAuthClientProvider and ClientCredentialsOAuthProvider, with older deployments of RFC7523OAuthClientProvider also potentially at risk.

Developers are urged to update to versions 1.30.0 and 2.2.0, which include patches to verify authorization-server issuers and reject unauthorized metadata. Organizations must configure the expected issuer and manage legacy OAuth registrations to mitigate risk.

For enhanced security, clearing old OAuth credentials, rotating exposed secrets, and revoking potentially compromised tokens is strongly recommended. Notably, MCP servers using this SDK and local clients providing their own authorization headers are immune to this vulnerability.

As AI systems become more autonomous, ensuring robust security measures against potential threats such as DNS hijacking and prompt injection is crucial.

Cyber Security News Tags:AI agent, AI security, Authentication, authorization server, client credential, Cybersecurity, identity provider, MCP, MCP server, OAuth, OAuth misconfiguration, Python SDK, security update, software patch, Vulnerability

Post navigation

Previous Post: Critical Flaws Addressed in OpenSSL and WolfSSL Updates
Next Post: OpenAI Enhances Codex with Continuous Security Monitoring

Related Posts

MessiahGPT AI Tool Fuels Cybercrime with Ransomware MessiahGPT AI Tool Fuels Cybercrime with Ransomware Cyber Security News
Global Mobile Networks Exploited by Hackers via SS7 and Diameter Global Mobile Networks Exploited by Hackers via SS7 and Diameter Cyber Security News
Linux Decrypts Apple’s Location Sharing Protocol Linux Decrypts Apple’s Location Sharing Protocol Cyber Security News
GitLab Vulnerability Exposes Private Repositories to Code Injections GitLab Vulnerability Exposes Private Repositories to Code Injections Cyber Security News
APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails Cyber Security News
PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Enhances Codex with Continuous Security Monitoring
  • Critical Flaw in MCP Python SDK Exposes AI Accounts
  • Critical Flaws Addressed in OpenSSL and WolfSSL Updates
  • Critical Citrix NetScaler Flaw Allows Remote Code Execution
  • OpenSSL Patches Critical DTLS Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Enhances Codex with Continuous Security Monitoring
  • Critical Flaw in MCP Python SDK Exposes AI Accounts
  • Critical Flaws Addressed in OpenSSL and WolfSSL Updates
  • Critical Citrix NetScaler Flaw Allows Remote Code Execution
  • OpenSSL Patches Critical DTLS Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark