A significant security vulnerability in the official MCP Python SDK has been identified, allowing malicious servers to intercept OAuth credentials. This flaw, revealed in a recent security advisory, affects applications using older versions of the SDK, potentially exposing sensitive credentials such as the client secret, authorization code, and PKCE proof key to attacker-controlled endpoints. The vulnerability is particularly critical for automated systems where human intervention is not required, scoring a 7.5 out of 10 on the severity scale.
The MCP, or Model Context Protocol, facilitates the integration of AI applications with external tools and data sources. The official Python SDK for MCP is used to build both servers and clients for this purpose. The flaw permits attackers to trick an application into communicating with a fraudulent login service, thereby capturing the credentials meant for a legitimate service. These stolen credentials can then be used to obtain an access token from the real login service, with the same permissions as the compromised application.
The security firm Cycode, which reported the flaw, demonstrated the vulnerability in a controlled test. The flaw has been addressed in SDK versions 1.30.0 and 2.2.0. However, merely upgrading is not enough for some configurations. Users employing ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider must also specify the correct login service using the 'issuer' parameter. Without this, the applications remain vulnerable to redirection by malicious servers.
Applications using the SDK as an MCP client over HTTP with certain OAuth providers are at risk if they connect to servers not under their control while holding valid credentials. To mitigate the risk, affected users should upgrade to the latest SDK versions, clear any existing OAuth client registrations, and rotate client secrets if there is a possibility of exposure. The advisory and Cycode's report, both published in September, confirm that no attacks exploiting this vulnerability have been observed to date.

