Flaw in Official MCP Python SDK Could Let Rogue Servers Steal Login Credentials
Security researchers have found a flaw in the official Python SDK for the Model Context Protocol (MCP), an open standard used to connect AI applications to outside tools and data. The issue allowed a malicious MCP server to trick a connected application into sending its login credentials, including a client secret, authorization code, and a one-time security key called a PKCE proof, to a server controlled by the attacker instead of the genuine login service.
Security firm Cycode, which reported the flaw, demonstrated that attackers could use these stolen credentials to request a valid access token from the real login service. That token would carry whatever permissions the original application had been granted. Because the client secret does not expire on its own, it remains usable until it is manually changed. In cases where a person is required to approve the sign-in, Cycode found that the approval page still looks completely genuine, making the attack hard to spot.
The flaw affects two automated login methods rated high severity (7.5) and one interactive method rated medium severity (6.5). It has been fixed in SDK versions 1.30.0 and 2.2.0, though no CVE identifier had been assigned as of 29 September.