Interestana
Home/News/MCP Python SDK Vulnerability Exposes OAuth Credentials
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

MCP Python SDK Vulnerability Exposes OAuth Credentials

MCP Python SDK Vulnerability Exposes OAuth Credentials

A significant security vulnerability has been identified within the official MCP Python SDK, potentially allowing malicious servers to intercept and steal OAuth credentials from applications that rely on this SDK for authentication. The maintainers of the SDK disclosed this issue in a security advisory, detailing how affected versions of the SDK could be tricked into sending sensitive authentication information to an attacker-controlled token endpoint. Specifically, the vulnerability enables a malicious MCP server to obtain the client secret, the authorization code, and the PKCE (Proof Key for Code Exchange) proof key. These pieces of information are crucial for establishing secure OAuth 2.0 sessions and, if compromised, could grant an attacker unauthorized access to user accounts or sensitive data within the applications using the vulnerable SDK. The MCP Python SDK is a software development kit designed to facilitate the integration of applications with services that utilize the Mobile Control Protocol (MCP). This protocol is often employed in scenarios requiring secure authentication and authorization, particularly in mobile environments or applications that need to interact with various backend services. By exploiting this flaw, an attacker could effectively impersonate a legitimate user or application, gaining access to resources they are not authorized to access. The advisory highlights that the vulnerability lies in how the SDK handles the communication with the token endpoint during the OAuth 2.0 authorization flow. When an application initiates an OAuth login process, it typically involves several steps, including obtaining an authorization code and then exchanging it for an access token. The compromised SDK versions incorrectly transmit critical components of this exchange, such as the client secret and the PKCE proof key, to a server specified by the attacker, rather than the legitimate authorization server. The security advisory explicitly states that the fix for this vulnerability is available in versions 1.30.0 and later of the MCP Python SDK. Users and developers employing earlier versions are strongly urged to update their SDK to the patched version immediately to mitigate the risk of credential theft. The implications of this vulnerability are broad, as any application utilizing the affected SDK versions for OAuth authentication is potentially at risk. This could include a wide range of web applications, mobile backends, and other services that rely on secure user sign-in processes. The maintainers have not specified the exact number of applications affected but emphasize the critical nature of the flaw, given the sensitive nature of OAuth credentials. The MCP Python SDK is a foundational component for many developers, and its compromise could lead to widespread security incidents if not addressed promptly. The advisory serves as a critical alert for the developer community to review their dependencies and ensure they are running the most secure version of the SDK. OAuth 2.0 is a widely adopted authorization framework that allows users to grant third-party applications limited access to their resources on another service without sharing their credentials. The client secret is a confidential key used by the client application to authenticate itself with the authorization server. The authorization code.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next