# Cycode reports a flaw in the official MCP Python SDK that lets a malicious server collect OAuth credentials

> Cycode says the MCP Python SDK could send client secrets to endpoints named by a malicious server. Versions 1.30.0 and 2.2.0 fix it; no CVE is assigned and no exploitation is reported.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/news/mcp-python-sdk-flaw-malicious-servers-steal-oauth-credentials

Cycode has reported a flaw in the official Python SDK for the Model Context Protocol (MCP) that lets a malicious MCP server steal OAuth credentials from a client, [The Hacker News reported](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html) on 29 September 2026. The maintainers' security advisory was published on 28 September, and patched versions exist. No CVE identifier had been assigned by 29 September, and the report says no active exploitation has been observed [[1]](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html).

## Background

MCP is the protocol through which AI assistants and coding agents connect to tool servers, such as a calendar, a code host or a database. When such a server needs the user's authorisation it can point the client to an OAuth authorisation server. The client must confirm that the server it is sending secrets to is the legitimate one; the report concerns a missing confirmation of that kind.

## What the report describes

Cycode found that a malicious MCP server could supply false details about its authorisation server and so redirect the client to a token endpoint controlled by the attacker. The SDK did not verify the endpoint before sending the client secret, the authorisation code and the PKCE proof key [[1]](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html).

The affected releases are versions 1.9.1 through 1.29.1 of the 1.x line and 2.0.0 through 2.1.1 of the 2.x line. The fixes are 1.30.0 and 2.2.0. Four OAuth provider classes are named: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider and the deprecated RFC7523OAuthClientProvider. The severity is given as 7.5 (high) for unattended providers and 6.5 for the interactive one; the report as summarised does not name the scoring system [[1]](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html).

Release notes dated 7 September 2026 describe issuer checks. The report's advice is to upgrade at once, to pass an issuer parameter for two of the providers so that the legitimate authorisation server is named, to clear stored OAuth client registrations after the upgrade, and to rotate client secrets and revoke tokens if an untrusted server was ever contacted [[1]](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html).

> A client that hands a secret to the wrong server still has to connect to it. FireAI, the on-device firewall for macOS developed by HisnLabs, asks before an app first reaches a new destination. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

The flaw concerns software built with the SDK, so the exposed group is developers and users of applications that embed it and connect to third-party MCP servers. The report does not limit the issue to one operating system, so a Mac running such a client is within scope [[1]](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html). Applications that only connect to servers the user runs and trusts carry less exposure, because the attack needs a malicious server to be contacted.

## Recommendations

1. Check whether any tool you use embeds the MCP Python SDK, and update it to 1.30.0, 2.2.0 or later.
2. Connect MCP clients only to servers whose operator you can identify.
3. After upgrading, clear stored OAuth client registrations, as the report advises.
4. Rotate client secrets and revoke tokens for any server you doubt.

## Relevance to FireAI

FireAI does not read the contents of an encrypted connection, so it cannot tell that an OAuth exchange went to a wrong endpoint, and it does not patch the SDK. It works at the connection level: a Python process reaching a host it has not reached before triggers a prompt, [Investigate](https://hisnlabs.com/en/docs/investigate-a-connection) shows the company and country behind it, and a [per-app rule](https://hisnlabs.com/en/docs/per-app-rules) can limit an app to the destinations you expect.

> Agent tools reach many servers, and each new one is a decision. FireAI names the app and the destination before the connection opens. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The account relies on one press report of Cycode's findings. It does not say which popular applications embed the affected SDK versions, and it does not report exploitation. The rating and the absence of a CVE may change after 29 September.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [The Hacker News, 29 September 2026: Official MCP Python SDK flaw can let malicious servers steal OAuth credentials](https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html)
