Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory.

Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Attack Update: Top 5 Attack-IPs auf doode.info – 13.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 74.7.241.36 — 1240 requests (recent log) 89.167.35.212 — 683 requests (recent log) 216.73.216.103 — 335 requests (recent

Show HN: Mail Memories – A desktop app to rescue photos from Gmail

Show HN: Mail Memories – A desktop app to rescue photos from Gmail Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 20.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 213.209.159.175 — 263 requests (recent log) 89.167.35.212 — 143 requests (recent log) 167.172.177.125 — 93 requests (recent