Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
Se muestra el contenido original; la traduccion localizada aun no esta disponible.
Qué ocurrió
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
Por que importa
The development may change operating conditions or market expectations around Security. Further confirmation and measurable outcomes matter.
Entidades afectadas
Ver evidencia
1 articulos · 1 informe original · 1 independientes
- The Hacker NewsFuente primaria · Respalda · EN · 100%Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials ↗
Afirmaciones
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials Observado
Conflictos
No se detectaron conflictos importantes en la evidencia disponible.
Cronología
- Primera publicación
Movimiento del mercado posterior al evento
La reacción del mercado aún no está disponible para este activo y periodo.