A Critical Vulnerability in the Official MCP Python SDK Exposes OAuth Credentials, Leaving Thousands of Developers and Organizations at Risk
A recently discovered flaw in the official MCP (Microsoft Certified Partner) Python Software Development Kit (SDK) has left thousands of developers and organizations vulnerable to a severe security risk. The vulnerability, which can allow malicious servers to steal OAuth credentials, is especially concerning given the widespread use of OAuth for authentication and authorization across various online platforms.
The issue lies within the SDK’s implementation of the OAuth protocol, specifically in its handling of authorization codes. When an application requests access to sensitive data or resources on behalf of a user, it typically receives an authorization code that can be exchanged for an access token. However, due to a weakness in the MCP SDK’s code, this authorization code can be intercepted and used by malicious servers to obtain OAuth credentials, effectively allowing them to impersonate users and gain unauthorized access.
The scope of the vulnerability is significant, with thousands of developers using the MCP SDK to build applications that rely on OAuth for authentication. This includes a wide range of industries, from finance and healthcare to e-commerce and social media. The potential consequences are severe, as an attacker gaining OAuth credentials could use them to access sensitive data or perform malicious actions on behalf of a user.
To make matters worse, the vulnerability is not limited to specific applications or services that utilize the MCP SDK; rather, it affects any application that uses the vulnerable version of the SDK. This means that even if an organization has robust security measures in place, they may still be at risk if their developers are using the affected SDK.
The exposure of OAuth credentials can have far-reaching consequences, including identity theft and unauthorized access to sensitive data or resources. Given the widespread adoption of OAuth across various online platforms, a single compromised OAuth credential could potentially unlock multiple attack paths, making it essential for organizations to take immediate action to address this vulnerability.
For developers and organizations using the MCP SDK, it is crucial to update their code to the latest, patched version as soon as possible. Additionally, they should review their authentication and authorization protocols to ensure that no other vulnerabilities exist. By taking proactive steps to mitigate this risk, individuals can significantly reduce their exposure to potential attacks and protect sensitive data from unauthorized access.
Source: The Hacker News — 2026-09-29