Cycode has reported a flaw in the official Python SDK for the Model Context Protocol (MCP) that lets a malicious MCP server steal OAuth credentials from a client, The Hacker News reported on 29 September 2026. The maintainers' security advisory was published on 28 September, and patched versions exist. No CVE identifier had been assigned by 29 September, and the report says no active exploitation has been observed [1].
Background
MCP is the protocol through which AI assistants and coding agents connect to tool servers, such as a calendar, a code host or a database. When such a server needs the user's authorisation it can point the client to an OAuth authorisation server. The client must confirm that the server it is sending secrets to is the legitimate one; the report concerns a missing confirmation of that kind.
What the report describes
Cycode found that a malicious MCP server could supply false details about its authorisation server and so redirect the client to a token endpoint controlled by the attacker. The SDK did not verify the endpoint before sending the client secret, the authorisation code and the PKCE proof key [1].
The affected releases are versions 1.9.1 through 1.29.1 of the 1.x line and 2.0.0 through 2.1.1 of the 2.x line. The fixes are 1.30.0 and 2.2.0. Four OAuth provider classes are named: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider and the deprecated RFC7523OAuthClientProvider. The severity is given as 7.5 (high) for unattended providers and 6.5 for the interactive one; the report as summarised does not name the scoring system [1].
Release notes dated 7 September 2026 describe issuer checks. The report's advice is to upgrade at once, to pass an issuer parameter for two of the providers so that the legitimate authorisation server is named, to clear stored OAuth client registrations after the upgrade, and to rotate client secrets and revoke tokens if an untrusted server was ever contacted [1].
Implications for Mac users
The flaw concerns software built with the SDK, so the exposed group is developers and users of applications that embed it and connect to third-party MCP servers. The report does not limit the issue to one operating system, so a Mac running such a client is within scope [1]. Applications that only connect to servers the user runs and trusts carry less exposure, because the attack needs a malicious server to be contacted.
Recommendations
- Check whether any tool you use embeds the MCP Python SDK, and update it to 1.30.0, 2.2.0 or later.
- Connect MCP clients only to servers whose operator you can identify.
- After upgrading, clear stored OAuth client registrations, as the report advises.
- Rotate client secrets and revoke tokens for any server you doubt.
Relevance to FireAI
FireAI does not read the contents of an encrypted connection, so it cannot tell that an OAuth exchange went to a wrong endpoint, and it does not patch the SDK. It works at the connection level: a Python process reaching a host it has not reached before triggers a prompt, Investigate shows the company and country behind it, and a per-app rule can limit an app to the destinations you expect.
Limitations
The account relies on one press report of Cycode's findings. It does not say which popular applications embed the affected SDK versions, and it does not report exploitation. The rating and the absence of a CVE may change after 29 September.
Try FireAI, by HisnLabs free for 17 days.