A security vulnerability in the MCP Python SDK, identified as GHSA-qx49-fqc8-xw99, allows malicious servers to steal OAuth credentials. While patched versions 1.30.0 and 2.2.0 are available, simply upgrading the SDK is insufficient. Users must also explicitly configure the `issuer` parameter for `ClientCredentialsOAuthProvider` and `PrivateKeyJWTOAuthProvider` to prevent credential theft. AI
IMPACT Requires developers using the MCP Python SDK to perform manual configuration beyond a simple version update to secure their applications.
RANK_REASON Security vulnerability in a specific software library requiring manual intervention beyond a version upgrade.
- ClientCredentialsOAuthProvider
- GHSA-qx49-fqc8-xw99
- GitHub
- MCP
- ModelContextProtocol
- OAuth
- PrivateKeyJWTOAuthProvider
- Python Package Index
- Python SDK
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →