Threat Intelligence

Flaw in Official MCP Python SDK Could Let Rogue Servers Steal Login Credentials

The Hacker News · 29 Sept 2026
Key Takeaway If your business uses tools built on the MCP Python SDK, update to version 1.30.0 or 2.2.0 immediately and rotate any associated OAuth client secrets.

Security researchers have found a flaw in the official Python SDK for the Model Context Protocol (MCP), an open standard used to connect AI applications to outside tools and data. The issue allowed a malicious MCP server to trick a connected application into sending its login credentials, including a client secret, authorization code, and a one-time security key called a PKCE proof, to a server controlled by the attacker instead of the genuine login service.

Security firm Cycode, which reported the flaw, demonstrated that attackers could use these stolen credentials to request a valid access token from the real login service. That token would carry whatever permissions the original application had been granted. Because the client secret does not expire on its own, it remains usable until it is manually changed. In cases where a person is required to approve the sign-in, Cycode found that the approval page still looks completely genuine, making the attack hard to spot.

The flaw affects two automated login methods rated high severity (7.5) and one interactive method rated medium severity (6.5). It has been fixed in SDK versions 1.30.0 and 2.2.0, though no CVE identifier had been assigned as of 29 September.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.