A security advisory for the official Model Context Protocol Python SDK warns that affected OAuth client implementations can send OAuth credentials to an attacker-controlled token endpoint when they connect to a malicious MCP server. Exposed material can include the client secret, authorization code, and PKCE verifier, potentially enabling an attacker to obtain a valid access token.

The reported issue affects HTTP MCP clients using specified OAuth providers and is fixed in version 1.30.0 on the 1.x line and 2.2.0 on the 2.x line. For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider, users must also set issuer=; upgrading alone does not bind those credentials to the expected authorization server.

Action for AI platform teams

  • Upgrade affected SDK deployments and explicitly configure the expected issuer where required.
  • Do not allow credential-bearing clients to connect to untrusted MCP servers.
  • Rotate client secrets and revoke tokens if an affected client may have connected to an untrusted server.
  • Review stored OAuth client registrations created before the fix.

No attacks exploiting the issue were reported in the advisory, but the remediation is relevant anywhere MCP clients can discover third-party servers.

Source: MCP Python SDK advisory; The Hacker News.

By Allan