Official MCP Python SDK OAuth credential theft security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Official MCP Python SDK clients were found vulnerable to an OAuth credential theft flaw that let a malicious MCP server redirect login handling and capture secrets. The issue affected 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line, exposing the client secret, authorization code, and PKCE proof key. Fixed versions 1.30.0 and 2.2.0 stop the redirect abuse, and no attacks have been reported.
Related Happenings
RabbitMQ OAuth client secret leak security flaw (CVE-2026-57219)
Vulnerability
H score32
First: 14.07.2026 16:48
Last: 14.07.2026 16:48
Sources 1
About this happening:
RabbitMQ disclosed CVE-2026-57219, a management API flaw that can leak an OAuth client secret from GET /api/auth and enable full broker takeover in affecte...
RabbitMQ OAuth client secret leak security flaw (CVE-2026-57219)
VulnerabilityAbout this happening: RabbitMQ disclosed CVE-2026-57219, a management API flaw that can leak an OAuth client secret from GET /api/auth and enable full broker takeover in affecte...
Gitea Docker images X-WEBAUTH-USER header trust bypass (CVE-2026-20896)
Vulnerability
H score38
First: 06.07.2026 19:28
Last: 06.07.2026 19:28
Sources 1
About this happening:
Researchers observed in-the-wild probing of CVE-2026-20896 in Gitea Docker images 13 days after disclosure, turning a recently patched critical authentication by...
Gitea Docker images X-WEBAUTH-USER header trust bypass (CVE-2026-20896)
VulnerabilityAbout this happening: Researchers observed in-the-wild probing of CVE-2026-20896 in Gitea Docker images 13 days after disclosure, turning a recently patched critical authentication by...
N8n sandbox escape flaws (multiple vulnerabilities)
Vulnerability
H score41
First: 04.02.2026 15:00
Last: 04.02.2026 15:00
Sources 1
About this happening:
Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...
N8n sandbox escape flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...
Timeline
-
29.09.2026 09:08 1 articles · 1h ago
Official MCP Python SDK release notes add issuer checks to block OAuth credential redirection
Mitigation Patch UpdateRelease notes for the official MCP Python SDK's 1.30.0 and 2.2.0 versions added issuer checks so a client verifies the login service it expects before accepting authorization details, closing the redirect path that could send OAuth credentials to a different endpoint.
Show sources
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08
-
29.09.2026 09:08 2 articles · 1h ago
Security advisory details OAuth credential theft in the official MCP Python SDK
Initial DisclosureOn September 28, the security advisory and Cycode's writeup described a malicious MCP server tricking applications built on the official MCP Python SDK into sending the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, and neither source reported any attacks using the flaw.
Show sources
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com — 29.09.2026 09:08