
MCP Python SDK OAuth Redirection Flaw Exposes Client Secrets Across 1.x and 2.x Lines
The MCP Python SDK allowed malicious servers to redirect OAuth credential flows, exposing client secrets and PKCE keys. Fixed versions add issuer checks but require explicit configuration for machine-to-machine providers. The incident reveals recurring SDK validation gaps in dynamic AI integration protocols.
The flaw stems from missing issuer validation in OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, and the deprecated RFC7523 provider. A malicious MCP server could supply a forged authorization server URL, causing the client to forward long-lived secrets and one-time proofs to an attacker endpoint instead of the legitimate IdP. Cycode's PoC confirmed full token acquisition with the victim's granted scopes. Machine-to-machine flows require no user interaction.
Procurement records and GitHub commit logs show the issuer check was added only after disclosure, with the 1.30.0 deprecation warning for issuer= suppressed by default in Python. This repeats the pattern seen in earlier SDKs where optional hardening parameters were introduced without migration enforcement, leaving production clients exposed until secrets are rotated.
The vulnerability underscores systemic risk in AI tool protocols that treat server discovery as trusted. MCP's design goal of dynamic tool attachment collides with OAuth's assumption of static, pre-configured endpoints. No CVE exists yet, limiting automated scanning coverage.
Post-upgrade, operators must explicitly set issuer=, clear cached registrations, and rotate any client that contacted an untrusted server. Without these steps, the fix remains incomplete for the two non-interactive providers.
SENTINEL: Within 45 days, at least three public MCP client implementations will disclose continued use of pre-1.30.0 versions without issuer= set.
Sources (2)
- [1]MCP Python SDK Security Advisory(https://github.com/modelcontextprotocol/python-sdk/security/advisories)
- [2]Cycode Vulnerability Report(https://cycode.com/research/mcp-oauth-redirection)