MCP Python SDK patches high-risk OAuth credential flaw
Maintainers of the Model Context Protocol Python SDK have patched a high-severity OAuth weakness that could let a malicious MCP server steal authentication credentials and potentially take over accounts. The flaw affects the official Python implementation of MCP, an open protocol originally introduced by Anthropic to connect artificial-intelligence applications with external tools and data. The…
The Model Context Protocol Python SDK has addressed a critical OAuth vulnerability that could enable malicious servers to steal authentication credentials and potentially gain control over user accounts. This flaw impacts the official Python implementation of MCP, an open protocol developed by Anthropic for connecting artificial-intelligence applications with external tools and data.
The security advisory assigns a severity rating of 7.5 out of 10 for unattended authentication providers, indicating a high risk. Affected software versions range from 1.9.1 to 1.29.1 and from 2.x pre-release 2.0.0a1 through 2.1.1. The vulnerability arises from gaps in OAuth discovery, allowing an attacker-controlled server to manipulate the process of determining which authorization server handles authentication and where an authorization code is exchanged for a token.
The SDK failed to validate the authorization-server metadata "issuer" on every discovery path, and stored or pre-provisioned client credentials were inconsistently bound to the correct authorization server. This combination of weaknesses could enable a malicious server to select the endpoint receiving authentication material, potentially obtaining sensitive information such as client secrets, authorization codes, and PKCE code verifiers.
Cycode researchers demonstrated an end-to-end proof of concept, showing that stolen credentials could be forwarded to the legitimate authorization server to obtain a valid access token. The attack can still direct users to the genuine identity provider's login page, but after successful authentication, the vulnerable client may send the resulting code and related credentials to the attacker's token endpoint.
The vulnerability affects certain authentication handlers, including OAuthClientProvider, ClientCredentialsOAuthProvider, and PrivateKeyJWTOAuthProvider. Maintainers recommend upgrading to version 2.2.0 for the current branch or 1.30.0 for the maintained 1.x branch. Users of specific authentication providers must configure the issuer parameter manually to ensure proper protection against this vulnerability.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.