A significant security vulnerability in the Model Context Protocol (MCP) Python SDK has been identified, potentially allowing malicious actors to hijack AI agent accounts by exploiting OAuth authentication weaknesses.
Understanding the OAuth Flaw
This flaw impacts MCP clients using OAuth to connect to identity providers such as Google, Okta, or Microsoft Entra ID, especially when these clients unknowingly interact with unverified servers. The MCP protocol is designed to facilitate AI tools in connecting with external data sources, but this flaw exposes clients to potential security breaches.
The problem arises from the SDK’s over-reliance on data from MCP servers, which can be manipulated by attackers to redirect OAuth exchanges to their own controlled infrastructure, bypassing legitimate security measures.
Technical Details of the Exploit
The exploitation process starts when a rogue MCP server responds to authorization-server discovery requests with a 404 error, leading the SDK to follow a fallback path. This path accepts OAuth configurations directly from the MCP server, without verifying the legitimacy of the OAuth issuer.
Attackers can then present a legitimate login interface from trusted providers while directing the OAuth token endpoint to a malicious server. This deception allows attackers to gain access tokens by sending authorization codes and other credentials to their endpoint.
Cycode has highlighted that this flaw compromises credential-binding protections, allowing attackers to impersonate legitimate servers and misuse stored credentials.
Impacted Versions and Mitigation
Several versions of the MCP Python SDK are affected, including 1.9.1 to 1.29.1 in the 1.x series and 2.0.0 to 2.1.1 in the 2.x series. Affected OAuth providers include OAuthClientProvider and ClientCredentialsOAuthProvider, with older deployments of RFC7523OAuthClientProvider also potentially at risk.
Developers are urged to update to versions 1.30.0 and 2.2.0, which include patches to verify authorization-server issuers and reject unauthorized metadata. Organizations must configure the expected issuer and manage legacy OAuth registrations to mitigate risk.
For enhanced security, clearing old OAuth credentials, rotating exposed secrets, and revoking potentially compromised tokens is strongly recommended. Notably, MCP servers using this SDK and local clients providing their own authorization headers are immune to this vulnerability.
As AI systems become more autonomous, ensuring robust security measures against potential threats such as DNS hijacking and prompt injection is crucial.
