Official MCP Python SDK Vulnerability Allows Malicious Servers to Steal OAuth Credentials

AI-generated NewsSnap summary based on source reporting.
Published: 2026-09-29
Category: technology
Source: The Hacker News

A high-severity flaw (rated 7.5) has been discovered in the official Model Context Protocol (MCP) Python SDK, which could allow malicious MCP servers to trick applications into divulging OAuth credentials. Affected versions sent client secrets, authorization codes, and PKCE proof keys to attacker-controlled token endpoints. Patches are available in versions 1.30.0 and 2.2.0.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai