What matters in AI.

Subscribe

Cycode found a vulnerability that let an MCP server steal OAuth credentials

Upgrade the SDK to version 2.2.0 or 1.30.0 to remove the vulnerability.

Researchers at Cycode found a vulnerability in versions 1.9.1 through 2.1.1 of the MCP Python SDK of Anthropic. An MCP server that an attacker controls can steal OAuth credentials from a user. The attacker can possibly get control of the account. Cycode told the MCP team of Anthropic, and the team released fixes in versions 2.2.0 and 1.30.0. Organizations that operate a version with the vulnerability must upgrade.

How the attack works

The vulnerability is in the OAuth discovery process of the SDK (software development kit). An attacker can control the MCP server and change the authentication flow. The server can then capture client secrets and authorization codes.

Why it is hard to see

Cycode found that the victim can go to the correct identity provider. The login looks usual. But credentials that the login makes can go to infrastructure that the attacker controls.

What is at risk

Cycode found that the effect can be more than one account. The permissions of the OAuth client set the risk. Credentials that an attacker steals can give access to these items:

  • connected cloud services
  • internal APIs
  • data stores
  • deployment infrastructure

Refresh tokens and long-lived client secrets can also give the attacker continuous access.

What to do

Upgrade to version 2.2.0 or 1.30.0. Then examine the OAuth registrations and the credentials that an attacker can get through the vulnerability.

Sources

  1. MCP Python SDK Flaw Exposed OAuth Credentials to Account TakeoverCybersecurity Insiders
AI MATTER · NEWS · AI MATTER · NEWS ·8 OCT2026

Posted

Tags

Learn the terms in this story

More in Security

All Security news