A high-severity flaw in the official Model Context Protocol (MCP) Python Software Development Kit (SDK) could let a malicious MCP server steal OAuth credentials and take over an account.
Application security firm Cycode detailed the flaw in research published Sept. 28, 2026. MCP, created by Anthropic, connects AI applications to external tools and data.
Cycode found that affected clients could send a client secret, authorization code, and Proof Key for Code Exchange (PKCE) verifier to an attacker-controlled endpoint. The attacker could then exchange them for a valid access token at the real login provider. In interactive sign-ins, the victim saw a genuine login page before the MCP server appeared to fail.
The weakness lay in how the SDK verified the login provider. The maintainers’ advisory said that check was missing on some or all discovery paths, so a server publishing no protected resource metadata could name the victim’s real provider as the issuer while routing the token exchange to itself.
Handing over the PKCE verifier defeats its purpose of stopping a stolen authorization code from being reused. Cycode noted that the client secret outlives the session, so an attacker can keep minting tokens, with the client’s full access, until the secret is rotated.
The issue affected versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 in HTTP clients using OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated RFC7523OAuthClientProvider.
The advisory rated it High, with a Common Vulnerability Scoring System (CVSS) score of 7.5 for the two machine-to-machine providers, while the interactive provider was scored 6.5 because a user must initiate the sign-in.
Upgrading Alone May Not Be Enough
The patched releases, 1.30.0 and 2.2.0, shipped on Sept. 7, 2026, and their release notes presented the issuer checks as behavior changes, not security fixes. The advisory followed on Sept. 28, crediting Cycode’s researcher alongside several other reporters.
For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, the advisory said upgrading changes nothing until users specify the expected login provider with an issuer setting. On 1.30.0, the reminder to set it is a standard deprecation warning, which Python hides by default.
Users of RFC7523OAuthClientProvider, which lacks an issuer option, must switch providers. After upgrading, stored OAuth client registrations should also be cleared so they are recreated with the login provider bound.
The flaw does not reach MCP servers built with the SDK, local stdio clients, or clients that supply their own tokens.
Neither Cycode’s research nor the advisory mentions any exploitation in the wild. As of Sept. 29, the advisory listed no Common Vulnerabilities and Exposures (CVE) identifier.
On affected versions, the advisory’s only workaround is connecting OAuth-enabled clients solely to trusted MCP servers. Users who may have connected to an untrusted MCP server before upgrading should rotate the client secret and revoke tokens at the login provider.