Maintainers of the official Model Context Protocol Python SDK have disclosed an OAuth validation weakness that could allow a malicious MCP server to redirect sensitive login material to an attacker-controlled authorization endpoint. The issue affects SDK clients that connect over HTTP and use specified OAuth provider classes.
The client trusted authorization-server information
According to the project advisory, affected clients could send a client secret, authorization code and PKCE verifier to an authorization server selected through untrusted MCP metadata. An attacker receiving those values could attempt to exchange them for an access token carrying the permissions granted to the application.
The affected ranges include versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1. Fixes are available in versions 1.30.0 and 2.2.0. Some machine-to-machine provider configurations also require an explicit issuer setting after the upgrade.
Credential rotation may be required
Teams should inventory MCP clients, upgrade supported branches and verify issuer configuration rather than treating the package update as the only control. Clients that connected to untrusted servers should have tokens revoked and long-lived secrets rotated. SectechMedia tracks related deployment risks in its cyber-physical security coverage.

Leave a Reply