A security vulnerability has been identified in the MCP Python SDK, affecting versions 1.9.1–1.29.1 and 2.0.0–2.1.1. The flaw allows a malicious MCP server to intercept an application's OAuth credentials, including client secrets and authorization codes, by misdirecting the client to an attacker-controlled token endpoint. This could lead to unauthorized access to the application's full permissions. Remediation involves upgrading the SDK, explicitly providing the issuer URL for OAuth providers, and rotating compromised secrets. AI
IMPACT Potential for credential theft in applications using the MCP Python SDK, impacting security and data integrity.
RANK_REASON Security advisory detailing a vulnerability in a specific software library.
- ClientCredentialsOAuthProvider
- Common Vulnerability Scoring System
- MCP Python SDK
- OAuth
- PrivateKeyJWTOAuthProvider
- RFC7523OAuthClientProvider
- Sept 28
- Sept 29
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →