Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

MCP Python SDK flaw could let malicious servers steal OAuth credentials

Maintainers of the Model Context Protocol's Python SDK rated the OAuth flaw high severity; Cycode showed it could turn stolen secrets into a working access token.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1A flaw in the MCP Python SDK could let a malicious MCP server collect OAuth secrets meant for a real login service.
  • 2Maintainers rated it high severity with a CVSS score of 7.5. Upgrading to 1.30.0 or 2.2.0 is not enough on its own: unattended clients must also pass an issuer setting, and stored registrations must be cleared.
  • 3Teams should upgrade, bind clients to their login server, clear stored registrations and rotate secrets if exposure is possible.

The news

A flaw in the official MCP Python SDK could let a malicious server capture the OAuth credentials an AI application uses to log in to real services, according to a security advisory the project's maintainers published on GitHub on September 28, 2026.

The Model Context Protocol (MCP) is a standard for connecting AI applications to outside tools and data through MCP servers. The advisory, GHSA-qx49-fqc8-xw99, covers the SDK's client-side OAuth support, the code an application uses to obtain access tokens before calling a protected MCP server. OAuth is the widely used standard that lets an app act on a user's or system's behalf without handling a password.

According to the advisory, the SDK's OAuth client did not always verify the login service's identity, known as the issuer, or record which login service its saved credentials belonged to. Versions 1.9.1 to 1.29.1 lacked both safeguards everywhere; 2.0.0 to 2.1.1 lacked them only when a server published no protected resource metadata or returned a 403 insufficient_scope error. On both lines, ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider had no way to name their login service. A hostile or hijacked MCP server could use these gaps to steer the client to an attacker-run endpoint, which would receive the client secret, authorization code and PKCE code verifier, a one-time proof designed to stop intercepted codes from being reused, intended for the real login service.

Security firm Cycode, which The Hacker News identified as the discoverer, said in a September 28 write-up by researcher Yuval Elbar that it tested the full chain against a real authorization server with PKCE enforcement. The attacker took the stolen items to the genuine login provider, received a valid access token and confirmed access to the account. Cycode said the attacker inherits whatever permissions the client had, and that if a refresh token is issued, access can be renewed without further action from the victim.

The advisory rates the issue high severity, with a CVSS score of 7.5 for unattended providers such as ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, and 6.5 for the interactive OAuthClientProvider, where a person starts the sign-in. It lists no CVE identifier, and The Hacker News said no attacks had been reported. Affected releases run from 1.9.1 up to, but not including, 1.30.0, and from 2.0.0a1 up to, but not including, 2.2.0. Versions 1.30.0 and 2.2.0 contain the fix, but the advisory says users of those two unattended providers are protected only once they also pass an issuer parameter, and that registrations saved without an issuer, including any saved by 1.x before 1.30.0, must be cleared. The advisory credits eight GitHub accounts as reporters. The GitHub release notes for 1.30.0 show a September 7 date, and The Hacker News said both patched versions shipped that day, labeled as a behavior change rather than a security fix.

The advisory says the risk applies only to applications that use the SDK as an MCP client over HTTP with one of four OAuth providers, and that may connect to an MCP server they do not fully trust while holding credentials for a real login service. MCP servers built with the SDK, local clients that communicate over standard input and output, and clients that attach their own tokens are not affected.

The numbers

Advisory severity score
CVSS 7.5 (high), unattended providers
Score for interactive OAuthClientProvider
6.5, per the advisory
Affected 1.x versions
1.9.1 to before 1.30.0
Affected 2.x versions
2.0.0a1 to before 2.2.0
Patched versions
1.30.0 and 2.2.0
GitHub accounts credited as reporters
8

Why CEOs should care

For CTOs and engineering leaders building AI agents, this is a supply chain problem in the plumbing that connects agents to company systems. If an agent can be pointed at a third-party MCP server while it holds OAuth credentials for a real service, a single bad server could walk away with a working token. The advisory's steps are specific: upgrade to 1.30.0 or 2.2.0, pass the issuer parameter to the ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider so the client only talks to its own login server, clear stored OAuth client registrations once, and rotate client secrets and revoke tokens if the client may have connected to an untrusted server.

For CISOs, the harder question is visibility. Which internal tools and products use the MCP Python SDK as a client, which versions are deployed, and which MCP servers are they allowed to reach? Cycode noted that on older versions the only workaround is to connect solely to MCP servers you trust. That argues for an approved list of MCP servers and for scoping each agent's OAuth permissions narrowly, since a stolen token carries everything the client was granted.

Buyers of AI agent platforms should ask vendors whether their products embed the MCP Python SDK, when they upgraded, and whether they rotated credentials. A fix that shipped labeled as a behavior change may not have triggered the urgency a security patch would.

The bigger picture

Companies are giving AI agents access to real business systems, and protocols like MCP are the connectors that make that possible. That makes the connector code a high-value target: a flaw there affects every application built on it. This case also shows a disclosure pattern security teams should watch for, where a fix lands weeks before the advisory that explains why it matters. Teams that update dependencies only for labeled security fixes can fall behind.

What’s next

Watch for a CVE assignment, for downstream agent frameworks and products to publish their own guidance, and for any reports of exploitation. Teams that cannot upgrade should restrict their clients to MCP servers they trust until they can move to the patched releases.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Model Context ProtocolCycodeOAuthAI agents

Earlier coverage of GitHub

All GitHub coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.