{"id":10087,"date":"2026-09-29T07:11:46","date_gmt":"2026-09-29T07:11:46","guid":{"rendered":"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/09\/29\/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials\/"},"modified":"2026-09-29T07:11:46","modified_gmt":"2026-09-29T07:11:46","slug":"official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials","status":"publish","type":"post","link":"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/09\/29\/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials\/","title":{"rendered":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials"},"content":{"rendered":"<p>\u200bA malicious MCP server could trick an application built on the official\u00a0MCP Python SDK\u00a0into handing over the OAuth credentials it uses to log in to a real service, the SDK&#8217;s maintainers said in a security advisory.<\/p>\n<p>Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and\u00a0A malicious MCP server could trick an application built on the official\u00a0MCP Python SDK\u00a0into handing over the OAuth credentials it uses to log in to a real service, the SDK&#8217;s maintainers said in a security advisory.<\/p>\n<p>Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and\u00a0\u00a0The Hacker News<\/p>","protected":false},"excerpt":{"rendered":"<p>\u200bA malicious MCP server could trick an application built on the official\u00a0MCP Python SDK\u00a0into handing over the OAuth credentials it uses to log in to a real service, the SDK&#8217;s maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the&hellip;&nbsp;<a href=\"https:\/\/news.cybertechworld.co.in\/index.php\/2026\/09\/29\/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-credentials\/\" class=\"\" rel=\"bookmark\">Read More &raquo;<span class=\"screen-reader-text\">Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials<\/span><\/a><\/p>\n","protected":false},"author":0,"featured_media":10088,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_themeisle_gutenberg_block_has_review":false,"footnotes":""},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts\/10087"}],"collection":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/comments?post=10087"}],"version-history":[{"count":0,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/posts\/10087\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/media\/10088"}],"wp:attachment":[{"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/media?parent=10087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/categories?post=10087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.cybertechworld.co.in\/index.php\/wp-json\/wp\/v2\/tags?post=10087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}