The maintainers of the Model Context Protocol (MCP) Python SDK disclosed a critical authentication flaw that exposes OAuth credentials to malicious servers. Versions before 1.30.0 contain a vulnerability that allows attackers to intercept and steal sensitive authentication materials, including client secrets, authorization codes, and PKCE proof keys.
The vulnerability stems from improper validation of token endpoints. When an application uses the official MCP Python SDK to authenticate with a service via OAuth, the SDK failed to verify whether the token endpoint was legitimate before sending authentication credentials to it. A malicious MCP server could exploit this gap by directing the client to send these sensitive materials to an attacker-controlled endpoint instead of the actual authorization server.
The exposure is severe because OAuth credentials serve as the gateway to user accounts and connected services. A client secret allows attackers to impersonate the application itself. An authorization code grants temporary access to user data. A PKCE proof key, while typically single-use, represents part of the authentication chain and could assist in further attacks. Together, these materials enable account takeover and lateral movement into integrated services.
The SDK maintainers released version 1.30.0 as the remediation. Organizations using MCP Python SDK must update immediately to patch the flaw. The vulnerability affects any application that integrates the SDK and relies on OAuth for authentication with external services. This includes applications built on Claude's Model Context Protocol extensions, which handle integrations with developer tools, databases, and enterprise systems.
The attack surface extends across development teams using MCP to build AI-assisted applications. If a malicious actor controls or compromises an MCP server that a client application connects to, the attacker gains a direct path to steal authentication credentials. No user action beyond normal application operation is required to trigger the vulnerability. The flaw activates passively during the standard OAuth authentication flow.
The MCP architecture allows applications to connect to multiple servers, each potentially providing different functionality. A compromised or malicious server in this ecosystem poses a systemic risk. Developers may not immediately recognize when they are connecting to an untrusted endpoint, making this vulnerability particularly dangerous in development and testing environments where security controls are often relaxed.
The fix validates token endpoints before sending credentials to them. This ensures that authentication requests only reach the intended authorization server. Organizations should treat this update as urgent given the direct credential exposure involved. Any system running vulnerable versions should be patched without delay.
Developers should audit their MCP implementations to confirm they run version 1.30.0 or later. Teams should also review any custom MCP servers in their infrastructure for similar endpoint validation gaps. The vulnerability underscores the importance of validating server endpoints in protocol implementations, particularly in authentication flows where credentials are at stake.
