Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Summary
A security vulnerability has been discovered in the official MCP Python SDK. Malicious MCP servers can exploit this flaw to steal OAuth credentials used by applications built with the SDK. Affected versions would send sensitive authentication data, including the client secret and PKCE proof key, to attacker-controlled token endpoints.
IFF Assessment
This vulnerability allows attackers to steal OAuth credentials, which can lead to unauthorized access to user accounts and sensitive data.
Severity
The vulnerability allows for attacker-controlled redirection to malicious servers, leading to the theft of sensitive OAuth credentials including the client secret and PKCE proof key, representing a significant impact on confidentiality and potentially integrity.
Defender Context
This vulnerability highlights the importance of securing SDKs and client-side authentication flows. Defenders should ensure applications are updated to patched versions of the MCP Python SDK and monitor for any signs of credential compromise. It also underscores the need for robust validation of token endpoints to prevent man-in-the-middle attacks.