MCP Python SDK Flaw Could Expose OAuth Credentials to Malicious Servers

Security researchers at Cycode have disclosed a high-severity vulnerability in the Model Context Protocol Python SDK that could allow a malicious MCP server to redirect OAuth credentials to infrastructure controlled by an attacker.

The issue affects applications using the SDK as an HTTP MCP client with its built-in OAuth providers. Cycode says an attacker could abuse weaknesses in the SDK’s authorization-server discovery process to capture credentials including client secrets, authorization codes and PKCE verification data.

The flaw has been fixed in mcp 2.2.0 and 1.30.0.

How the attack worked

MCP allows AI applications to connect to external tools and services. When one of those services requires OAuth authentication, the client must determine which authorization server handles the login and where token requests should be sent.

According to Cycode’s research, the Python SDK did not consistently verify the identity of that authorization server when it fell back to older discovery methods.

A malicious MCP server could deliberately trigger one of those fallback paths and provide manipulated OAuth metadata. That could cause the SDK to send sensitive token-exchange data to the attacker’s endpoint while still directing the user to the legitimate identity provider for the visible login step.

That distinction makes the attack harder to recognize. The user could see the genuine Google, Okta, Azure AD or other authorization page rather than a phishing site, while the later token exchange was redirected elsewhere.

Cycode says its proof of concept captured both an OAuth authorization code and the PKCE code_verifier, along with client credentials. Those values could then be submitted to the legitimate authorization server to obtain an access token.

The MCP project’s security advisory confirms that affected clients could disclose a client secret, authorization code and PKCE verifier. The potential impact depends on the permissions granted to the compromised OAuth client.

Who needs to update

Affected releases include MCP Python SDK versions 1.9.1 through 1.29.1 and 2.x releases before 2.2.0. Users should upgrade to mcp 2.2.0 or 1.30.0 or later. Developers using machine-to-machine authentication may also need to update their configuration, while applications that stored OAuth registrations under older versions should recreate them after upgrading.

Organizations that may have connected affected clients to an untrusted MCP server should also rotate exposed credentials and revoke relevant tokens. Updating the SDK prevents the flaw from being exploited going forward, but it cannot undo any credential theft that may already have occurred.