MCP Python SDK OAuth Credential Theft via Malicious Server Redirect
A vulnerability in the official MCP Python SDK allowed malicious servers to manipulate OAuth flows, tricking client applications into leaking sensitive credentials such as client secrets and authorization codes. This represents a classic OAuth redirect/hijack class of flaw within a widely-used SDK, meaning any downstream application consuming the library inherited the vulnerability without necessarily knowing it. The risk is compounded because stolen OAuth tokens grant attackers the full permission scope of the compromised application, potentially enabling data exfiltration, account takeover, or lateral movement. This incident underscores the danger of trusting third-party SDKs without rigorous vetting and timely patching processes, especially in authentication-critical code paths.
Tactical Insight
Immediate actions
- Upgrade the MCP Python SDK to the patched version and apply any additional mitigation steps documented by maintainers for specific OAuth provider configurations.
- Audit all applications using the affected SDK versions to identify exposed OAuth credentials, rotating any client secrets or tokens that may have been compromised.
- Validate OAuth redirect URIs and enforce strict origin/server validation in all authentication flows.
Long-term improvements
- Establish a software composition analysis (SCA) pipeline to continuously track third-party SDK versions and flag known vulnerabilities before they reach production.
- Implement least-privilege OAuth scopes so that even if tokens are stolen, the blast radius of credential theft is minimized.
- Maintain a verified inventory of all third-party libraries and SDKs used across projects, with defined SLAs for patching critical security issues.
Detection measures
- Monitor OAuth token usage logs for anomalous access patterns, such as tokens being used from unexpected IP addresses or at unusual times.
- Set up alerts for SDK dependency updates and CVE disclosures related to authentication libraries in use.
- Integrate secrets scanning tools into CI/CD pipelines to detect accidental credential exposure during build and deployment.