MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers

Vulnerability in MCP Python SDK pre-1.30.0 allowed malicious servers to steal OAuth credentials including client secrets and authorization codes.
Table of Contents
    Add a header to begin generating the table of contents

    A vulnerability in the official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal OAuth credentials from client applications that integrate with external services. The flaw, disclosed by SDK maintainers on September 29, affects versions prior to 1.30.0 and stems from the SDK sending sensitive authentication tokens to attacker-controlled endpoints during the OAuth flow.

    MCP Python SDK Leaked Client Secrets and Authorization Codes to Token Endpoints

    The vulnerability occurs when applications built with the affected SDK versions attempt to authenticate with external services using OAuth. During the standard OAuth flow, the SDK transmitted the client secret, authorization code, and PKCE (Proof Key for Code Exchange) proof key to the token endpoint specified by the MCP server. An attacker operating a malicious MCP server could configure their own token endpoint address, causing the SDK to send these credentials directly to attacker infrastructure rather than the legitimate OAuth provider.

    This design flaw creates a supply chain vulnerability that affects any application using vulnerable SDK versions to integrate with external services. The OAuth client secret acts as a shared password between the application and the OAuth provider, while the authorization code represents the user’s consent to grant access. Together, these credentials provide sufficient authentication material for an attacker to impersonate the legitimate application and request access tokens on behalf of compromised users.

    OAuth Theft Enables Cross-Service Account Impersonation

    OAuth credentials stolen through this vulnerability allow attackers to obtain access tokens for the services the application integrates with. Once an attacker possesses a valid access token, they can interact with the victim’s account on the integrated service using the application’s identity. This impersonation bypasses normal login controls because the OAuth provider recognizes the stolen credentials as legitimate authentication from a trusted application.

    The scope of accessible data depends on the OAuth permissions the application requests during the authorization flow. Applications that request broad permissions to read user data, modify account settings, or access sensitive resources would grant attackers equivalent capabilities through the stolen credentials. The vulnerability’s impact extends beyond the immediate MCP application to encompass all services that trust the application’s OAuth credentials.

    Fixed Versions Validate Token Endpoints Before Transmitting Credentials

    SDK maintainers released patched versions 1.30.0 and later that address the vulnerability by validating the token endpoint before transmitting sensitive authentication material. The fix ensures that client secrets, authorization codes, and PKCE proof keys are only sent to verified OAuth provider endpoints rather than arbitrary addresses controlled by MCP servers.

    Developers using the MCP Python SDK should update to version 1.30.0 or later immediately. The supply chain nature of the vulnerability means that every application built with affected SDK versions remains vulnerable until the developer upgrades the SDK dependency and redeploys the application. Applications that do not use OAuth integration are not affected, but SDK maintainers recommend upgrading regardless to maintain consistent security posture across the codebase.

    Supply Chain Vulnerabilities in Official SDKs Amplify Downstream Risk

    The disclosure highlights the amplification effect of vulnerabilities in widely used software development kits. When an official SDK maintained by the protocol developers contains a security flaw, every application built with that SDK inherits the vulnerability. Developers trust official SDKs to implement security-sensitive operations correctly, making SDK vulnerabilities particularly dangerous because they bypass the individual application security reviews that might catch similar flaws in custom-written code.

    MCP’s decision to publish a security advisory notifying affected developers demonstrates responsible disclosure practice. Many SDK vulnerabilities go unannounced beyond release notes, leaving developers unaware that a dependency update addresses an active security risk. The explicit advisory raises the visibility of the fix and signals to development teams that immediate action is required rather than treating the update as routine maintenance.

    Applications using the MCP Python SDK for OAuth integration should audit their current SDK version and prioritize the upgrade to 1.30.0 or later. Development teams should also review application logs for any suspicious OAuth authentication attempts that may indicate exploitation attempts during the vulnerability window.

    Related Posts