
Anthropic's MCP Python SDK had a flaw that let rogue servers steal OAuth credentials
A high-severity vulnerability in Anthropic's official MCP Python SDK allowed a malicious server to steal OAuth credentials and take over user accounts. The flaw, CVE-2026-52869, is now patched in versions 1.30.0 and 2.2.0.










