A critical vulnerability in the Minecraft Control Protocol (MCP) SDKs allowed malicious servers to intercept OAuth credentials. The issue, reported by Cycode and WorkOS, stemmed from the SDKs failing to verify the OAuth issuer, enabling attackers to trick clients into sending sensitive information like client secrets. While patches exist for the MCP Python and Rust SDKs, simply upgrading is insufficient; users must explicitly configure trusted issuers to prevent exploitation. A proof-of-concept client demonstrates this vulnerability, highlighting the need for clients to verify their login providers before sharing credentials. AI
IMPACT Requires developers to pin OAuth issuers to prevent credential theft in MCP SDK integrations.
RANK_REASON The item discusses a specific vulnerability and its mitigation in a software development kit, which falls under tooling.
- CVE-2026-59822
- CVE-2026-63127
- Cycode
- GHSA-qx49-fqc8-xw99
- LiteLLM
- MCP
- Minecraft Control Protocol
- Node.js
- OAuth
- Roster
- Rust SDK
- TypeScript
- WorkOS
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →