A recent security advisory reveals a significant flaw in the official Model Context Protocol (MCP) Python SDK, potentially allowing malicious servers to capture OAuth credentials. This vulnerability could lead to unauthorized access to services, emphasizing the need for immediate updates to the latest SDK versions, specifically 1.30.0 and 2.2.0.
Understanding the MCP SDK Vulnerability
The MCP Python SDK, integral for establishing connections between artificial intelligence applications and external tools, was found to have a critical flaw. According to the SDK maintainers, a rogue MCP server could manipulate the SDK into sending OAuth credentials, including the client secret, authorization code, and PKCE proof key, to a server controlled by an attacker.
Once these credentials are intercepted, attackers can generate valid access tokens from legitimate login services. This exposes applications to significant security risks, as the tokens could carry extensive permissions granted to the app. Cycode, the security firm that identified the flaw, successfully demonstrated this vulnerability, highlighting its potential impact.
Affected Versions and Severity Scores
The vulnerability affects versions 1.9.1 through 1.29.1 of the 1.x line and 2.0.0 through 2.1.1 of the 2.x line. The issue has been rated with a high severity score of 7.5 for non-interactive providers, which do not require user intervention, and 6.5 for interactive providers, where user authentication is involved. As of September 29, no CVE identifier had been assigned to this vulnerability.
The flaw arises when an MCP client queries the server for its login service location. A compromised server can redirect the client to a malicious login service, capturing sensitive credentials. This issue is exacerbated for machine-to-machine interactions that bypass user confirmation.
Steps for Mitigation and Resolution
To mitigate this vulnerability, users should upgrade to versions 1.30.0 or 2.2.0. In these updates, the SDK verifies expected login services before processing any credentials. However, users of ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider must also specify the issuer of their credentials to ensure security. For deprecated providers without this option, transitioning to supported versions is recommended.
After upgrading, it is crucial to clear any saved OAuth client registrations, as older registrations are not linked to specific login services. Additionally, if there is any suspicion of prior exposure, rotating client secrets and revoking tokens is advised. The advisory emphasizes the importance of connecting only to trusted MCP servers.
The release notes, issued on September 7, initially documented these changes under behavior modifications rather than as a security fix. The security advisory was later released on September 28, alongside Cycode’s detailed analysis. While no active exploitation has been reported, the disclosure credits multiple researchers, including those from Cycode.
Looking Ahead
This incident underscores the importance of regular software updates and vigilant security practices. Organizations using the MCP Python SDK should implement the recommended updates promptly to safeguard their systems against potential threats. Continuous monitoring and adherence to security advisories remain crucial in mitigating risks associated with software vulnerabilities.
