National Cyber Warfare Foundation (NCWF)

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials


0 user ratings
2026-09-29 06:57:04
milo
Developers , Blue Team (CND) , Attacks
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.

Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers
Blue Team (CND)
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.