PulseAugur
EN
LIVE 09:16:48

MCP Python SDK OAuth flaw allows credential theft

A security vulnerability has been identified in the MCP Python SDK, affecting versions 1.9.1–1.29.1 and 2.0.0–2.1.1. The flaw allows a malicious MCP server to intercept an application's OAuth credentials, including client secrets and authorization codes, by misdirecting the client to an attacker-controlled token endpoint. This could lead to unauthorized access to the application's full permissions. Remediation involves upgrading the SDK, explicitly providing the issuer URL for OAuth providers, and rotating compromised secrets. AI

IMPACT Potential for credential theft in applications using the MCP Python SDK, impacting security and data integrity.

RANK_REASON Security advisory detailing a vulnerability in a specific software library.

Read on dev.to — MCP tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

MCP Python SDK OAuth flaw allows credential theft

How we ranked this

Signal score
1 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Security advisory detailing a vulnerability in a specific software library.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
1 days old
Coverage has settled into its steady-state source set.

Full methodology in our editorial standards.

COVERAGE [1]

  1. dev.to — MCP tag TIER_1 English(EN) · ScriptMasterLabs ·

    What Is the MCP Python SDK OAuth Flaw? (Sept 29, 2026)

    <p>Today's security advisory on the official MCP Python SDK is worth more than a skim: a malicious MCP server could steal an app's OAuth credentials — client secret, authorization code, and the PKCE proof key — by answering one question wrong: "where do I log in?"</p> <p><strong>…