MCP Python SDK Fix Closes OAuth Credential Redirect Flaw
The official MCP Python SDK has fixed a flaw that could let a malicious server redirect OAuth secrets, authorization codes and PKCE proof keys during AI tool sign-ins.

A flaw in the official MCP Python SDK created a way for a malicious Model Context Protocol server to pull OAuth credentials away from the service an application meant to use, The Hacker News reported from the maintainers' advisory and Cycode's analysis.
The affected SDK versions could send three sensitive pieces of the login exchange to an attacker-controlled token endpoint: the client secret, the authorization code and the PKCE proof key.
Fixed releases are now available as versions 1.30.0 and 2.2.0.
The issue matters because MCP is becoming a standard connection layer between AI applications and outside tools or data sources.
The Python SDK is used to build MCP servers and clients, so a weakness in the way those clients validate login metadata can sit directly in the path between an AI application and the services it is allowed to access.
The vulnerable flow began when an MCP client asked the server it was connecting to where the relevant authorization server could be found.
On affected versions, that response was not always checked closely enough.
A hostile server could point the client toward an attacker-operated login service, or serve metadata that named the user's real service while routing credentials somewhere else.
Once those values left the intended flow, the attacker could use them to request an access token from the genuine login service.
Cycode demonstrated that exchange in testing and found that the resulting token carried the permissions already granted to the application.
The client secret also remained useful until it was rotated, turning a one-time login problem into a longer-lived credential exposure.
PKCE is meant to reduce the value of a stolen authorization code by requiring a matching proof key during the token exchange.
In this case, the same flawed path could hand over the proof key too, removing that protection for the affected flow.
The maintainers rated the weakness high for providers that run without a person present, with a CVSS score of 7.5.
The score falls to 6.5 for the interactive provider because a user still has to approve the sign-in.
No CVE had been assigned as of September 29.
Interactive sign-ins create another constraint on exploitation, but not a complete defense.
Cycode said the approval page still showed the legitimate service, which means a user could authorize what appeared to be a normal login while the token exchange was being redirected.
The repaired SDK now checks that the authorization server's issuer matches the expected resource metadata before it proceeds.
For teams building AI tools around MCP, the immediate control is straightforward: update the SDK, rotate exposed secrets where a vulnerable flow may have run, and review integrations that accept authorization metadata from servers they do not fully control.




















