The official Python SDK for the Model Context Protocol (MCP) has a vulnerability that could let a malicious server steal OAuth credentials from applications built with it. The flaw, disclosed in a security advisory, affects versions 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line. The SDK's maintainers say the issue stems from the client not always verifying the authorization server's identity, allowing an attacker to redirect credential exchange to their own endpoint.
When an MCP client needs to log in, it asks the server for the authorization server's address. In affected versions, the client may accept a malicious address without proper validation. This can lead to the client sending its client secret, authorization code, and PKCE proof key to the attacker. The proof key is meant to prevent reuse of stolen codes, so its exposure defeats that protection. With these credentials, the attacker can request a valid access token from the real login service, gaining whatever permissions the app was granted. The client secret is long-lived, so it remains valid until changed.
The flaw is rated high (7.5) for machine-to-machine providers that run without human interaction, and 6.5 for the interactive provider where a user must approve sign-in. The advisory notes that in the interactive case, the user sees the genuine login page, so nothing appears suspicious. The fix is in versions 1.30.0 and 2.2.0, which now verify the expected login service before fetching any details. However, for the ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, upgrading alone is insufficient; users must also pass 'issuer=' to specify the login service, otherwise the client still follows the server's instructions. The deprecated RFC7523OAuthClientProvider lacks this option, so users should migrate to another provider.
Cycode, the security firm that reported the flaw, demonstrated the full attack in a test. No active exploits have been reported, and the advisory credits eight reporters. The issuer checks were initially listed as behavior changes in the release notes on September 7, with the advisory following on September 28. Users are advised to upgrade, clear stored OAuth client registrations, and rotate secrets if they suspect exposure. For older versions, the only workaround is to connect only to trusted MCP servers.