A flaw in the official Python SDK for the Model Context Protocol lets a hostile MCP server walk off with the OAuth credentials an AI application uses to sign in to a real service.
The project’s maintainers put out patched builds, numbered 1.30.0 and 2.2.0. Security firm Cycode reported the bug and demonstrated the whole exchange working in a test.
Login is where it turns ugly. A client asks the server it is connecting to where its authorization service lives, and on the affected builds the SDK did not always verify that answer. A malicious server can therefore point the client at a token endpoint of its own, and the client obliges by surrendering its client secret, authorization code and PKCE proof key, the very material that protection exists to keep from being replayed when a code leaks.
A thief holding that bundle can go back to the genuine identity provider and trade it for a live access token. Whatever rights the application was granted travel along with it. Because the client secret never expires on its own, rotating it is the only way to shut access off.
Scoring puts the severity at 7.5 for two providers that run with nobody at the keyboard, and 6.5 where a human must approve the sign-in. As of September 29, no CVE identifier had been issued.
Patching alone does not close the gap: two providers still need an issuer value naming the login service those credentials belong to. Users should also clear stored OAuth client registrations once.
