Story thread · 2 reports / 2 sources
Anthropic’s Official MCP Python SDK Had an OAuth Credential-Stealing Flaw That Let Any Malicious Server Hijack Your Login
forkast.news · 2h
How the coverage leans
Across 2 sources · syndicated copies counted once
The official Python SDK for the Model Context Protocol — the open standard connecting AI applications to external tools and data — had a vulnerability that let any malicious MCP server steal the OAuth credentials its clients used to log in to real services. The flaw, disclosed September 28 and tracked as GHSA-qx49-fqc8-xw99, carries a […]
First report: Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials — thehackernews.com, 1d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.