Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

OAuth Credential Leak via Official MCP Python SDK Vulnerability (Pre‑Fix Versions)

A flaw in the official MCP Python SDK could cause applications to inadvertently send OAuth client secrets, authorization codes, and PKCE proof keys to attacker‑controlled token endpoints. The issue affects all pre‑1.30.0 SDK releases and underscores the need for rigorous third‑party component assurance in control‑centric programs.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

OAuth Credential Leak via Official MCP Python SDK (Pre‑1.30.0 Versions)

What Happened — The official MCP Python SDK (versions < 1.30.0) automatically forwards the OAuth client secret, authorization code, and PKCE proof key to the token endpoint supplied by the caller. A malicious MCP server can present an attacker‑controlled token endpoint, causing the SDK to hand over those credentials to the attacker. The SDK maintainers disclosed the issue in a security advisory and released a fix in version 1.30.0.

Why It Matters for Trust & Control Assurance

  • Demonstrates a supply‑chain control gap: a third‑party library can exfiltrate privileged authentication material without the application’s knowledge.
  • Highlights the need for continuous third‑party risk monitoring and evidence collection to prove that all dependencies meet your security posture.
  • Provides a concrete audit‑ready artifact (SDK version, remediation timeline) that maps to the control objective of “vendor and component oversight.”

Who Is Affected

  • SaaS and cloud‑native vendors that embed the MCP Python SDK in their services.
  • Any organization (finance, health, media, etc.) that integrates the SDK for OAuth‑based authentication to Microsoft‑cloud services.

Recommended Actions

  • Upgrade every instance of the MCP Python SDK to v1.30.0 or later.
  • Run a dependency‑scanning pass to locate any lingering vulnerable SDK copies.
  • Enable runtime monitoring of outbound token requests to detect unexpected token‑endpoint destinations.
  • Document the remediation steps and version evidence for audit readiness.

Technical Notes

  • Vulnerability type: Credential exposure via SDK logic flaw (no CVE assigned).
  • Affected versions: All releases prior to 1.30.0.
  • Fixed in: 1.30.0 (released by the SDK maintainers).
  • Attack vector: Exploitation of a third‑party dependency that forwards OAuth secrets to an attacker‑controlled endpoint.

Source: The Hacker News – Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

📰 Original Source
https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →