Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
- Posted on September 29, 2026
- By The Hacker News
- 0 Views
- 1 min read
In brief
Generating AI summary…
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.