Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
If you’ve built on the official MCP Python SDK, check your version. It didn’t validate the authorization server’s identity, so a malicious MCP server could talk a client into handing over its OAuth client credentials, then mint tokens with whatever scopes your app was granted. Fixed in 1.30.0 and 2.2.0 (affected: 1.9.1-1.29.1 and 2.0.0-2.1.1). Upgrading alone won’t save you - that client secret is long-lived, so rotate it too.