MCP Python SDK OAuth account takeover
A malicious HTTP MCP server can force a fallback OAuth discovery path, then receive a client's authorization code, client secret, and PKCE verifier after the user signs in at the legitimate provider.
Cycode found that MCP Python SDK versions 1.9.1 through 2.1.1 do not validate the authorization-server issuer on fallback discovery paths. A malicious server can return 404 for modern discovery, supply attacker-controlled token-endpoint metadata, and obtain OAuth material that lets it redeem a valid access token. Fixed releases are mcp 1.30.0 and 2.2.0; affected deployments must also clear stored registrations, rotate client secrets, revoke tokens where exposure is possible, and configure issuer= for unattended credential providers.
Takeaway
Treat an untrusted MCP server as an authentication boundary, not simply a tool endpoint. Patch affected clients and rotate credentials that could have entered an untrusted login flow.