The rapid adoption of Model Context Protocol is creating an important new security boundary that organisations need to understand: an MCP server should not automatically be treated as a trusted extension of the application connecting to it.

A newly disclosed flaw in the official MCP Python SDK demonstrates exactly why.

In affected versions, a malicious or compromised MCP server could manipulate OAuth discovery information and cause the MCP client to send sensitive authentication material to an attacker-controlled endpoint. This could include the OAuth client secret, authorization code and PKCE verifier, potentially allowing an attacker to obtain legitimate access tokens for the actual service the application was attempting to access.

The problem is especially significant for AI applications because MCP servers are increasingly being used to connect AI agents and assistants to external systems such as databases, cloud platforms, development environments and enterprise applications. These integrations may carry substantial privileges, meaning the compromise of an OAuth credential can extend well beyond the MCP connection itself.

The affected SDK versions include MCP Python SDK 1.9.1 through 1.29.1 and versions 2.0.0 through 2.1.1. The issue has been addressed in versions 1.30.0 and 2.2.0, which introduce stronger validation of the expected OAuth authorization-server issuer.

For ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider deployments, simply upgrading may not be sufficient. Administrators should also configure the expected issuer so that credentials are cryptographically and logically associated with the intended authorization server rather than following OAuth metadata supplied by an MCP server.

Organisations using MCP should therefore begin treating MCP servers similarly to other third-party integrations: establish which servers are trusted, restrict which systems and credentials they can access, monitor outbound authentication traffic, rotate credentials where exposure is suspected, and keep MCP client libraries updated.

This incident also illustrates a broader challenge emerging with AI infrastructure. AI agents increasingly sit between users, credentials, APIs and sensitive enterprise systems. A weakness in that intermediary trust layer can allow an attacker to compromise legitimate credentials without directly attacking the underlying application.

According to the disclosure, there is currently no indication that this vulnerability has been exploited in real-world attacks. Nevertheless, organisations experimenting with MCP should review their deployments now rather than waiting for attackers to turn architectural weaknesses into repeatable attack techniques.


A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

Source: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials via The Hacker News — published 29 Sep 2026.