MCP Python SDK Flaw Exposed OAuth Credentials to Account Takeover

Security researchers at Cycode uncovered a vulnerability in Anthropic’s Model Context Protocol (MCP) Python SDK that could allow a malicious MCP server to steal OAuth credentials and potentially take over user accounts.

The vulnerability, detailed in new research from Cycode, affected MCP Python SDK versions 1.9.1 through 2.1.1. By exploiting weaknesses in the SDK’s OAuth discovery process, an attacker-controlled MCP server could manipulate authentication flows and capture sensitive credentials including client secrets, authorization codes and PKCE proof keys.

What makes the attack particularly notable is that victims could still be sent to their legitimate identity provider to authenticate. While the login itself appeared normal, credentials generated during the process could ultimately be redirected to infrastructure controlled by the attacker, potentially providing everything needed to obtain a valid access token.

The impact could extend well beyond a single compromised account. Depending on the permissions granted to the OAuth client, stolen credentials could potentially provide access to connected cloud services, internal APIs, data stores and deployment infrastructure. Refresh tokens and long-lived client secrets could also give attackers a path to persistent access.

Cycode disclosed the vulnerability to Anthropic’s MCP team, and fixes were released in MCP Python SDK versions 2.2.0 and 1.30.0. Organizations running affected versions should upgrade and review OAuth registrations and credentials that may have been exposed.

The discovery highlights a broader security challenge emerging as MCP adoption grows: connecting AI applications and agents to enterprise systems creates new authentication and trust boundaries that attackers can target. As these integrations gain access to more sensitive systems and data, securing the protocols and credentials underpinning those connections will become increasingly important.

Join our LinkedIn group Information Security Community!

No posts to display