National Cyber Warfare Foundation (NCWF)

Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover


0 user ratings
2026-09-29 13:14:53
milo
Red Team (CNA)

Security researchers have disclosed a high-severity vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK. This flaw could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments that use HTTP transport and includes vulnerable SDK releases from versions 1.9.1 to 2.1.1. Research from Cycode […]


The post Anthropic MCP Python SDK Flaw Enables OAuth Credential Theft and Account Takeover appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Divya

Source: gbHackers
Source Link: https://gbhackers.com/anthropic-mcp-python-sdk-flaw/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.