Find notable cyber news and cases, enriched with sources, timelines, and signals.

Official MCP Python SDK OAuth credential theft security flaw

Vulnerability
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Official MCP Python SDK clients were found vulnerable to an OAuth credential theft flaw that let a malicious MCP server redirect login handling and capture secrets. The issue affected 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line, exposing the client secret, authorization code, and PKCE proof key. Fixed versions 1.30.0 and 2.2.0 stop the redirect abuse, and no attacks have been reported.

Related Happenings

RabbitMQ OAuth client secret leak security flaw (CVE-2026-57219)

Vulnerability
H score32 First: 14.07.2026 16:48 Last: 14.07.2026 16:48 Sources 1

About this happening: RabbitMQ disclosed CVE-2026-57219, a management API flaw that can leak an OAuth client secret from GET /api/auth and enable full broker takeover in affecte...

Gitea Docker images X-WEBAUTH-USER header trust bypass (CVE-2026-20896)

Vulnerability
H score38 First: 06.07.2026 19:28 Last: 06.07.2026 19:28 Sources 1

About this happening: Researchers observed in-the-wild probing of CVE-2026-20896 in Gitea Docker images 13 days after disclosure, turning a recently patched critical authentication by...

N8n sandbox escape flaws (multiple vulnerabilities)

Vulnerability
H score41 First: 04.02.2026 15:00 Last: 04.02.2026 15:00 Sources 1

About this happening: Two maximum-severity sandbox-escape flaws in n8n expose self-hosted and cloud instances to complete server takeover and credential theft. An authenticated us...

Timeline

  1. 29.09.2026 09:08 1 articles · 1h ago

    Official MCP Python SDK release notes add issuer checks to block OAuth credential redirection

    Mitigation Patch Update

    Release notes for the official MCP Python SDK's 1.30.0 and 2.2.0 versions added issuer checks so a client verifies the login service it expects before accepting authorization details, closing the redirect path that could send OAuth credentials to a different endpoint.

    Show sources
  2. 29.09.2026 09:08 2 articles · 1h ago

    Security advisory details OAuth credential theft in the official MCP Python SDK

    Initial Disclosure

    On September 28, the security advisory and Cycode's writeup described a malicious MCP server tricking applications built on the official MCP Python SDK into sending the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, and neither source reported any attacks using the flaw.

    Show sources