Official MCP Python SDK OAuth Flaw Lets Malicious Servers Steal Client Secrets, Fixed in 1.30.0 and 2.2.0
A high-severity flaw in the official MCP Python SDK let a malicious server redirect OAuth credentials to an attacker's endpoint; fixes ship in 1.30.0 and 2.2.0, with extra steps needed.
Overview
A flaw in the official Model Context Protocol (MCP) Python SDK could let a malicious MCP server steal the OAuth credentials a client uses to sign in to a real service, according to The Hacker News. The SDK’s security advisory, GHSA-qx49-fqc8-xw99, was published on September 28, 2026 and rates the flaw High. The fix is in SDK versions 1.30.0 and 2.2.0.
What We Know
- The bug. The advisory describes the problem as the SDK’s OAuth client support letting “the MCP server a client connected to decide where the client’s OAuth credentials were sent.” The Hacker News reports that affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled, because on those versions “the SDK did not always check that answer” when it asked the server where its login service was.
- Affected versions. The Hacker News lists 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line, with fixes in 1.30.0 and 2.2.0 respectively.
- Affected components. Per the advisory, the affected classes are OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider and the deprecated 1.x RFC7523OAuthClientProvider. The Hacker News says MCP servers built with the SDK, local (stdio) clients, and clients that attach their own tokens are not affected.
- Severity. The Hacker News reports a rating of 7.5 for the two providers that run without a person present, and 6.5 for the interactive provider. It adds that no CVE had been assigned as of September 29.
- Impact. According to The Hacker News, security firm Cycode reported the flaw and demonstrated the full exchange in a test. It says the resulting token carries whatever permissions the app was granted, and that the client secret keeps working until it is changed. For the interactive provider, The Hacker News says Cycode found the page a user approves is the genuine login page, “so nothing looks wrong.”
What Users Need To Do
Upgrading is not the whole fix for two providers. The Hacker News quotes the advisory as saying that for ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, “upgrading changes nothing until you also pass issuer=”. On 1.30.0, The Hacker News says, the warning about this is a standard deprecation warning, “which Python hides by default, so it is easy to miss.” The deprecated RFC7523OAuthClientProvider has no issuer option at all, so The Hacker News advises moving to one of the other two providers.
After upgrading, The Hacker News says to clear any stored OAuth client registrations once, because older ones are not tied to a login service. The advisory adds that if such a client may have connected to an untrusted MCP server, its owner should “rotate its client secret and revoke its tokens at the authorization server.” For earlier versions, the advisory states there is “no workaround other than connecting OAuth-enabled clients only to MCP servers you trust.”
Timeline
The Hacker News reports that the issuer checks first shipped in the 1.30.0 and 2.2.0 release notes on September 7, listed under behavior changes rather than as a security fix. It states that the advisory followed on September 28, the same day Cycode published its writeup, and that the advisory credits eight reporters, including Cycode’s researcher.
What We Don’t Know
- Exploitation. The Hacker News reports that neither the advisory nor Cycode describes any attacks using the flaw, and that none has been reported elsewhere.
- CVE assignment. As of September 29, no CVE had been assigned, per The Hacker News.
- Scale of exposure. The sources do not say how many applications use the affected OAuth providers against servers they do not control.
Context
The MCP is, in The Hacker News’ description, “an open standard for connecting AI applications to outside tools and data.” The flaw joins recent disclosures affecting AI coding tooling, including GitSpawn and Plugin4Shell, previously reported by The Machine Herald.