Anthropic's MCP Python SDK had a flaw that let rogue servers steal OAuth credentials

A high-severity security flaw in Anthropic's official Model Context Protocol (MCP) Python SDK could have allowed an attacker-controlled server to steal OAuth credentials and seize control of user accounts in any application built on top of it. The vulnerability, tracked as CVE-2026-52869 with a CVSS score of 7.5, was fixed on September 7, 2026 and publicly disclosed on September 28 by The Hacker News.
MCP has become the dominant protocol for connecting AI agents to external tools and services. Applications built on the official Python SDK use OAuth to authenticate with those services — which made the flaw particularly consequential: exploiting it exposed not just a token but potentially the entire connected service ecosystem of any user who interacted with a malicious server.
What the vulnerability did
The flaw sits in how the SDK handles OAuth server discovery. Normally, when a client connects to an MCP server, it fetches the server's authorization metadata from a well-known endpoint and validates that the issuer field matches the server it just connected to. The vulnerable versions of the SDK failed this check on certain discovery paths.
An attacker running a malicious MCP server could trigger a 404 response during the discovery phase, pushing the client into an unsafe fallback mode. In that fallback, the SDK accepted OAuth configuration directly from the server without validating the issuer's identity — letting the attacker supply a poisoned authorization endpoint. From there, the server could harvest the client's authorization codes, PKCE proof keys, and stored client secrets.
The advisory identified two root causes: the authorization server metadata issuer was not validated on every discovery path, and stored client credentials were not cryptographically bound to the authorization server they belonged to.
Affected versions and fix
All releases of the 1.x line from version 1.9.1 through 1.29.1 were vulnerable, along with the 2.x pre-release series from 2.0.0a1 through 2.1.1. Versions 1.30.0 and 2.2.0 contain the fix, which adds strict issuer validation on every discovery path and binds stored credentials to their intended authorization server.
Developers using the MCP Python SDK for OAuth-enabled integrations should upgrade immediately. Applications that use only local or stdio transports — which do not involve remote OAuth flows — are not affected.
MCP security concerns are not new
The MCP ecosystem has faced scrutiny from security researchers since its rapid adoption began earlier this year. Prior research demonstrated that malicious MCP servers could inject tool-use responses that manipulate an AI agent's reasoning. CVE-2026-52869 represents a different class of risk: not model manipulation, but direct credential theft through a broken authentication flow in the official SDK itself.
As first reported by The Hacker News, the security advisory identifier is GHSA-qx49-fqc8-xw99.
Originally reported by The Hacker News. Read the original article for additional details.
View original source