Story thread · 2 reports / 2 sources

Anthropic’s Official MCP Python SDK Had an OAuth Credential-Stealing Flaw That Let Any Malicious Server Hijack Your Login

forkast.news · 2h

How the coverage leans

Across 2 sources · syndicated copies counted once

The official Python SDK for the Model Context Protocol — the open standard connecting AI applications to external tools and data — had a vulnerability that let any malicious MCP server steal the OAuth credentials its clients used to log in to real services. The flaw, disclosed September 28 and tracked as GHSA-qx49-fqc8-xw99, carries a […]

First report: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com, 1d

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.