Cycode found a vulnerability that let an MCP server steal OAuth credentials
Upgrade the SDK to version 2.2.0 or 1.30.0 to remove the vulnerability.
Researchers at Cycode found a vulnerability in versions 1.9.1 through 2.1.1 of the MCP Python SDK of Anthropic. An MCP server that an attacker controls can steal OAuth credentials from a user. The attacker can possibly get control of the account. Cycode told the MCP team of Anthropic, and the team released fixes in versions 2.2.0 and 1.30.0. Organizations that operate a version with the vulnerability must upgrade.
How the attack works
The vulnerability is in the OAuth discovery process of the SDK (software development kit). An attacker can control the MCP server and change the authentication flow. The server can then capture client secrets and authorization codes.
Why it is hard to see
Cycode found that the victim can go to the correct identity provider. The login looks usual. But credentials that the login makes can go to infrastructure that the attacker controls.
What is at risk
Cycode found that the effect can be more than one account. The permissions of the OAuth client set the risk. Credentials that an attacker steals can give access to these items:
- connected cloud services
- internal APIs
- data stores
- deployment infrastructure
Refresh tokens and long-lived client secrets can also give the attacker continuous access.
What to do
Upgrade to version 2.2.0 or 1.30.0. Then examine the OAuth registrations and the credentials that an attacker can get through the vulnerability.
Sources
- MCP Python SDK Flaw Exposed OAuth Credentials to Account TakeoverCybersecurity Insiders
Posted