I Audited the MCP SDK OAuth Fix: 3 Checks Upgrading Misses
Last week the official MCP Python SDK shipped a fix for a credential theft bug, and the fix itself has a trap that a version check will not catch. I was researching the disclosure for my own MCP servers and the remediation notes stopped me cold: patch the package, and part of the vulnerability survives unless you also change how you construct your OAuth providers. Here is the short version. On September 28, a GitHub advisory landed on the modelcontextprotocol python-sdk repo: GHSA-qx49-fqc8-xw99, titled "OAuth client could send credentials to an authorization server chosen by the MCP server."
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in