Critical MCP Python SDK Flaw Lets Attackers Hijack OAuth for AI Agents
A critical security flaw has been discovered in the official Model Context Protocol (MCP) Python software development kit, which could enable hostile MCP servers to seize OAuth credentials and take over AI agent accounts.
The issue originates from the SDK's handling of authentication tokens over unencrypted HTTP links. When a client app contacts an untrusted MCP server, that server can capture the OAuth data exchanged in the session. Because the SDK fails to enforce rigorous validation of the server's identity, a malicious endpoint can obtain the token and reuse it to act as the original user.
Developers using the MCP Python SDK to embed AI agents in their applications constitute the primary at‑risk group. The vulnerability specifically impacts HTTP‑based MCP clients lacking extra protections such as TLS encryption or server certificate pinning. Settings that allow connections to third‑party or experimental MCP servers without proper vetting are particularly exposed.
If exploited, the bug could result in complete account takeover, unauthorized execution of agent tasks, and leakage of any data the agent handles. Since OAuth tokens typically grant extensive permissions, an attacker who grabs them could manipulate the AI agent, retrieve confidential outputs, or even push malicious commands to downstream systems.
The MCP SDK maintainers have confirmed the problem and said a patched release will be issued promptly. Until then they recommend developers limit MCP traffic to trusted, TLS‑encrypted endpoints, enable certificate verification, and avoid using the SDK where server identity cannot be guaranteed. Organizations should also consider rotating any potentially compromised OAuth tokens as a safety measure.
This finding joins a growing roster of supply‑chain‑related weaknesses affecting AI tools and developer libraries. Security specialists warn that as AI services become increasingly modular and distributed, the trustworthiness of underlying SDKs forms a vital defensive layer. Continuous monitoring, swift patch rollout, and strict network hygiene will likely remain essential tactics for mitigating comparable threats going forward.
Comments (0)
Be the first to comment.
Join the discussion