Official MCP Python SDK Flaw Let Malicious Servers Steal OAuth Secrets From AI Clients
A high-severity flaw in the official MCP Python SDK let a malicious server redirect OAuth token requests and walk away with client secrets and access tokens. Fixes are out.

A malicious MCP server only had to lie about one address to walk off with an AI client's keys. The official Model Context Protocol Python SDK, the library many developers use to connect AI apps to tools and data, contained a high-severity OAuth flaw that let a hostile server redirect a client's token exchange to an endpoint the attacker controlled.
When that happened, affected clients handed over the client secret, the authorization code, and the PKCE proof key. That is everything needed to mint a real access token.
One lie, three secrets
OAuth relies on the client knowing where the genuine authorization server lives. In vulnerable versions of the SDK, the client trusted the MCP server to tell it. A malicious server could simply point at its own token endpoint, and the client would dutifully send its credentials there.
Cycode, which found and reported the bug, demonstrated a full token exchange in a test. The stolen token carries whatever permissions the app was granted. Worse, the client secret stays valid until someone rotates it, so the damage can outlast a single session.
Severity depends on whether a human is in the loop. The two machine-to-machine providers, which need nobody present, score 7.5. The interactive provider scores 6.5, because a person still has to approve a login page, though that page can look entirely genuine. No CVE had been assigned as of September 29.
The bug is another reminder that the plumbing around AI agents is now a real attack surface, much like the prompt injection risks in Claude Code's auto mode.
Who needs to patch, and how
The affected ranges are 1.9.1 through 1.29.1, fixed in version 1.30.0, and 2.0.0 through 2.1.1, fixed in 2.2.0.
Upgrading is not the whole job for everyone. Apps using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider stay exposed until callers also pass an issuer= value naming the real login service. Without it, the new check has nothing to compare against.
After upgrading, developers should clear stored OAuth client registrations once. Any client that may have talked to an untrusted server should also have its secrets rotated, since a leaked secret does not expire on its own.
Plenty of setups are safe. MCP servers built with the SDK are not affected, and neither are local stdio clients or clients that attach their own tokens rather than running the SDK's OAuth flow.
A quiet fix, then a loud advisory
The timeline is a little unusual. The issuer checks first shipped on September 7, listed in the release notes under behavior changes rather than flagged as a security fix. The formal advisory followed on September 28, alongside Cycode's writeup.
That gap meant anyone skimming changelogs for security items could easily have missed the fix for three weeks. Neither the advisory nor Cycode reports any attacks in the wild.
Still, MCP is spreading fast as the default way to wire models into company systems, and OAuth secrets for those connections are exactly what attackers want. It fits a broader pattern of AI tooling becoming a target, including the supply chain attack worries around OpenAI's GPT-6 Astra. This one was caught by researchers first, and the patch is already out.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free