A high-severity OAuth credential-disclosure vulnerability in Anthropic's official Model Context Protocol (MCP) Python SDK can allow a malicious HTTP MCP server to capture OAuth client secrets, authorization codes, PKCE verifiers, and ultimately valid access tokens. The attack abuses authorization-server discovery: an attacker-controlled server returns a 404 for modern discovery to trigger a legacy fallback that does not validate the issuer, then supplies malicious authorization metadata or token endpoints while presenting a legitimate identity-provider login flow to the user.
The issue affects mcp versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1, including OAuthClientProvider, ClientCredentialsOAuthProvider, and PrivateKeyJWTOAuthProvider configurations using vulnerable OAuth providers. It is fixed in versions 1.30.0 and 2.2.0; organizations should upgrade, explicitly bind machine-to-machine or pre-provisioned credentials to the expected issuer, remove legacy stored registrations, and rotate exposed client secrets and revoke potentially compromised tokens. No CVE or confirmed exploitation had been reported.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Cycode and the MCP security advisory publicly disclosed a high-severity OAuth flaw in the MCP Python SDK. A malicious HTTP MCP server could exploit legacy discovery handling to route authorization codes, client secrets, and PKCE verifiers to attacker-controlled token infrastructure, enabling account takeover.
Anthropic released MCP Python SDK versions 1.30.0 and 2.2.0, adding expected authorization-service determination, metadata rejection for mismatched providers, and credential binding. The releases addressed OAuth discovery weaknesses affecting HTTP clients using untrusted MCP servers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.