Official MCP Python SDK credential-theft fix release (1.30.0, 2.2.0)
Security Patch Release
Summary
Hide ▲
Show ▼
The official MCP Python SDK shipped fixed releases that close an OAuth credential-stealing flaw affecting 1.x and 2.x clients. The patch is available in 1.30.0 and 2.2.0, which add issuer-check behavior before login details are fetched. The release matters because affected clients could send the client secret, authorization code, and PKCE proof key to an attacker-controlled endpoint.
Timeline
-
29.09.2026 09:08 2 articles · 1h ago
MCP Python SDK adds issuer checks in 1.30.0 and 2.2.0
Mitigation Patch UpdateThe official MCP Python SDK shipped issuer-check behavior in the 1.30.0 and 2.2.0 release notes on September 7, requiring the client to confirm the expected login service before it fetches authorization details and refusing mismatched issuers.
Show sources
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08
-
29.09.2026 09:08 1 articles · 1h ago
Security advisory warns of OAuth credential theft via malicious MCP server
Initial DisclosureA security advisory warned that a malicious MCP server could trick applications built on the official MCP Python SDK into sending the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, affecting 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line.
Show sources
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08