Back to all news
Security

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

The Hacker News·September 29, 2026·1 min read
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over OAuth credentials, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint. The fix is in versions 1.30.0 and later.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store