A malicious Model Context Protocol server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK maintainers said in a security advisory. Affected versions sent the client secret, the authorisation code and the PKCE proof key to a token endpoint the attacker controlled, which lets the attacker request a valid access token from the legitimate login service — and because the client secret is long-lived, it keeps working until it is rotated. Cycode, which reported the flaw, demonstrated the full exchange in a test and says the resulting token carries whatever permissions the application was granted. The fix shipped in versions 1.30.0 and 2.2.0; the flaw is rated high (7.5) for the two providers that run without a person present and 6.5 when scored for the interactive provider where someone must start the sign-in. No CVE had been assigned as of 29 September. The significance is architectural rather than incidental: MCP is the integration layer that gives AI agents their access to external tools and data, so a credential-theft primitive in its reference implementation sits directly beneath the agentic deployments that the rest of this week's stories describe.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-30 |
| Source | The Hacker News |
| Reliability | Tier 2 |