MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
Cycode has disclosed a high-severity OAuth vulnerability in Anthropic’s official Model Context Protocol (MCP) Python SDK that ...
A critical security flaw in the official MCP Python SDK could allow a malicious MCP server to steal OAuth credentials used to log in to real services, ...
Python SDK could allow a malicious MCP server to steal OAuth authentication material and take over AI agent accounts. The ...