MCP Python SDK: one malicious server was enough to collect your client secret
> TL;DR: A malicious MCP server could trick the official MCP Python SDK client into sending its client secret, authorization code and PKCE proof key to an attacker-controlled token endpoint. The flaw was fixed on September 7 in versions 1.30.0 and 2.2.0 — but the advisory is dated September 28: many deployments are still running affected versions.
The mechanism: the server answers the client's question
The SDK's OAuth flow works like this: the client asks the MCP server where the authorization server is. The server answers. That is where everything hinges.
In the affected versions, the SDK validated that answer insufficiently. A malicious server could return an attacker-controlled token endpoint — and the client would send the client secret, authorization code and PKCE proof key to it.
Cycode reported the flaw and demonstrated a full credential exchange: the stolen credentials are redeemed for a valid access token carrying the application's permissions. And the client secret is long-lived: exchange it once, and you have it for a long time.
Who is affected
Affected providers: OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, and the deprecated RFC7523OAuthClientProvider on 1.x. CVSS 7.5 for the two non-interactive providers, 6.5 for the interactive provider. No CVE assigned to date, no known active attacks.
What the upgrade does not do
This is the part most teams will miss:
In 1.30.0, the warning is a standard Python deprecation warning, hidden by default. It does not blink anywhere.
What to check right now
The takeaway
In the OAuth flow, the MCP server is the least trustworthy part of the chain — and yet it decides where the client sends its secrets. A client that trusts the discovery answer of any server makes the same mistake as a browser that follows a redirect without checking. The simple rule: an identity must never depend on the answer of an uncontrolled third party.
Building software? CleanIssue performs security audits for your product in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
Azure DevOps MCP flaw: hidden PR comments hijacking AI code-review agents
A flaw in Microsoft's Azure DevOps MCP server let a hidden pull-request comment hijack AI code-review agents, instructing them to approve malicious changes or leak repository content. Demonstrates the prompt-injection risk on the MCP tool-calling layer connecting AI agents to dev infrastructure.
OAuth 2.0 PKCE: when protection is disabled without knowing it
PKCE protects against authorization code interception. But when poorly implemented, it gives a false sense of security.
153 million driver's licenses sold on the dark web: the IDScan case
A dark-web service named Nexus was selling access to 153 million US and Canadian driver's licenses and 3 million travel documents. Krebs on Security links the breach to identity service IDScan. The FBI is investigating.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant ActionShield audits.