HackerFeeds

CyberSecurity News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

The Hacker News
· September 29, 2026

AI summary

A vulnerability in the official MCP Python SDK can be exploited by a malicious server to obtain OAuth credentials from an application using the SDK. The malicious server can trick the application into sending sensitive information, including the client secret, authorization code, and PKCE proof key, to a token endpoint controlled by the attacker. The SDK's maintainers have issued a security advisory regarding the flaw. The issue is resolved in versions 1.30.0 and later of the SDK.

Read the full article at The Hacker Newsthehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.