A newly disclosed high-severity OAuth vulnerability in Anthropic’s official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal authentication material and take over user accounts. The flaw affects HTTP-based MCP clients using vulnerable SDK releases and OAuth providers, enabling attackers to obtain client secrets,... Weiterlesen: MCP Python SDK OAuth Flaw Lets Malicious Servers Steal Credentials an…
Intelligence View
⚡ tsecurity.de Intelligence
MCP Python SDK OAuth Flaw Lets Malicious Servers Steal Credentials and Take Over Accounts
A newly disclosed high-severity OAuth vulnerability in Anthropic’s official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal …