A security advisory released by the maintainers of the official MCP Python SDK warns that a malicious MCP server can coax applications using the SDK into surrendering their OAuth credentials. The flaw allows an attacker‑controlled token endpoint to capture sensitive authentication data, potentially compromising the security of any service the application accesses.
The vulnerability affects certain versions of the SDK that automatically forward the client secret, the authorization code, and the PKCE proof key to the token endpoint specified by the server. When a malicious server supplies its own endpoint, the SDK unwittingly sends these credentials to the attacker, enabling credential theft.
According to the advisory, the exposed elements include the client secret—a critical component used to authenticate the application—along with the authorization code and the PKCE (Proof Key for Code Exchange) proof key, which together facilitate the OAuth flow. Disclosure of these items could allow an adversary to impersonate the legitimate application and gain unauthorized access to protected resources.
The maintainers have issued a fix that is included in SDK version 1.30.0 and later releases. Users of the affected SDK are urged to upgrade promptly to the patched version to prevent exploitation. No further technical details or remediation steps beyond the version update were provided in the advisory.
OAuth is a widely adopted open standard for delegated authorization, and PKCE is an extension designed to mitigate interception attacks in public clients. Vulnerabilities that expose OAuth credentials underscore the importance of keeping third‑party libraries up to date, as outdated SDKs can become vectors for sophisticated attacks.
<small>Source: The Hacker News — read the original story there.</small>