OAuth Credential Leak via Official MCP Python SDK (Pre‑1.30.0 Versions)
What Happened — The official MCP Python SDK (versions < 1.30.0) automatically forwards the OAuth client secret, authorization code, and PKCE proof key to the token endpoint supplied by the caller. A malicious MCP server can present an attacker‑controlled token endpoint, causing the SDK to hand over those credentials to the attacker. The SDK maintainers disclosed the issue in a security advisory and released a fix in version 1.30.0.
Why It Matters for Trust & Control Assurance
- Demonstrates a supply‑chain control gap: a third‑party library can exfiltrate privileged authentication material without the application’s knowledge.
- Highlights the need for continuous third‑party risk monitoring and evidence collection to prove that all dependencies meet your security posture.
- Provides a concrete audit‑ready artifact (SDK version, remediation timeline) that maps to the control objective of “vendor and component oversight.”
Who Is Affected
- SaaS and cloud‑native vendors that embed the MCP Python SDK in their services.
- Any organization (finance, health, media, etc.) that integrates the SDK for OAuth‑based authentication to Microsoft‑cloud services.
Recommended Actions
- Upgrade every instance of the MCP Python SDK to v1.30.0 or later.
- Run a dependency‑scanning pass to locate any lingering vulnerable SDK copies.
- Enable runtime monitoring of outbound token requests to detect unexpected token‑endpoint destinations.
- Document the remediation steps and version evidence for audit readiness.
Technical Notes
- Vulnerability type: Credential exposure via SDK logic flaw (no CVE assigned).
- Affected versions: All releases prior to 1.30.0.
- Fixed in: 1.30.0 (released by the SDK maintainers).
- Attack vector: Exploitation of a third‑party dependency that forwards OAuth secrets to an attacker‑controlled endpoint.
Source: The Hacker News – Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials