Full Report
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
Analysis Summary
# Vulnerability: OAuth Credential Leak in Official MCP Python SDK
## CVE Details
- **CVE ID**: Pending (No CVE assigned as of September 29, 2026)
- **CVSS Score**: 7.5 (High) for machine-to-machine providers; 6.5 (Medium) for interactive providers.
- **CWE**: CWE-20 (Improper Input Validation) / CWE-601 (URL Redirection to Untrusted Site)
## Affected Systems
- **Products**: Official Model Context Protocol (MCP) Python SDK
- **Versions**:
- **1.x Line**: 1.9.1 through 1.29.1
- **2.x Line**: 2.0.0 through 2.1.1
- **Configurations**: Applications acting as MCP clients over HTTP using the following OAuth providers:
- `OAuthClientProvider`
- `ClientCredentialsOAuthProvider`
- `PrivateKeyJWTOAuthProvider`
- `RFC7523OAuthClientProvider` (Deprecated)
- **Note**: Local (stdio) clients and clients attaching their own tokens are **not** affected.
## Vulnerability Description
A flaw in the SDK's OAuth implementation allows a malicious MCP server to redirect a client's authentication requests. When a client initiates a login, the SDK fails to validate the authorization server endpoint provided by the MCP server.
An attacker-controlled server can point the client to a malicious endpoint, causing the SDK to transmit sensitive credentials—including the **client secret**, **authorization code**, and **PKCE proof key**—directly to the attacker. Because the PKCE proof key is leaked alongside the code, the attacker can bypass intended one-time-use protections to obtain valid access tokens from the legitimate service.
## Exploitation
- **Status**: PoC available (demonstrated by Cycode).
- **Complexity**: Low to Medium (requires the victim to connect to a malicious MCP server).
- **Attack Vector**: Network (Remote).
## Impact
- **Confidentiality**: High (Leads to full account takeover and theft of long-lived client secrets).
- **Integrity**: High (Attacker gains permissions granted to the original application).
- **Availability**: Low/None (Primary impact is unauthorized access).
## Remediation
### Patches
Update the SDK to the following versions immediately:
- **1.x Line**: Version 1.30.0
- **2.x Line**: Version 2.2.0
### Workarounds
- **Trust-Based Limitation**: Only connect to MCP servers that are fully trusted.
- **Provider Migration**: Users of `RFC7523OAuthClientProvider` must migrate to `ClientCredentialsOAuthProvider` or `PrivateKeyJWTOAuthProvider` as the former cannot be fully secured in v1.x.
## Detection
- **Indicators of Compromise**: Monitor for unexpected OAuth token requests originating from unrecognized IP addresses using legitimate application credentials.
- **Detection Methods**: Inspect application logs for outgoing HTTP requests to unknown or suspicious token endpoints during the MCP handshake process.
## References
- **Vendor Advisory**: hxxps://github[.]com/modelcontextprotocol/python-sdk/security/advisories/GHSA-qx49-fqc8-xw99
- **Cycode Research**: hxxps://cycode[.]com/blog/mcp-python-sdk-oauth-account-takeover/
- **SDK Releases**: hxxps://github[.]com/modelcontextprotocol/python-sdk/releases/tag/v2.2.0