MCP Python SDK GHSA-qx49-fqc8-xw99 (CVSS 7.5): malicious server can steal OAuth credentials — fix 1.30.0 / 2.2.0
GitHub advisory GHSA-qx49-fqc8-xw99 (published 28 September 2026; Cycode write-up same day; The Hacker News 29 Sep) covers the official Model Context Protocol Python SDK (PyPI package mcp): in affected versions the OAuth client support (mcp.client.auth) let the MCP server decide where the client’s OAuth credentials were sent — authorization-server metadata issuer was not validated on every discovery path, and stored/pre-provisioned client credentials were not bound to their authorization server. A malicious or compromised MCP server could therefore receive the client_secret, authorization code and PKCE code_verifier (or a signed client assertion under PrivateKeyJWTOAuthProvider) meant for the real login service. Affected: 1.9.1 through 1.29.1 (no issuer check / binding on any path); 2.0.0 through 2.1.1 (missing on legacy metadata fallback and 403 insufficient_scope paths); on both lines ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider had no way to name their issuer. Not affected: MCP servers built with the SDK, stdio clients, clients that attach their own tokens/headers. GHSA rates High 7.5 for unattended providers; interactive OAuthClientProvider scored 6.5 (UI:R). No CVE ID assigned on the advisory as of 29 Sep 2026. No in-the-wild exploitation stated. Distinct from desk google-mcp-toolbox-ssrf-14540-20260731 (Google mcp-toolbox SSRF) and GHSA-jpw9-pfvf-9f58 (session principal bypass). Primary: GitHub GHSA-qx49-fqc8-xw99; researcher: Cycode; wire: THN 29 Sep.
- Product
- Model Context Protocol Python SDK (PyPI: mcp) — OAuth client (mcp.client.auth)
- Versions
- Affected: 1.9.1–1.29.1 and 2.0.0–2.1.1 (also pre-releases >=2.0.0a1 <2.2.0 per GHSA). Fixed: 1.30.0 (1.x) and 2.2.0 (2.x). After upgrade, ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider must pass issuer=; clear unbound stored OAuth registrations once.
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (GHSA HIGH FOR UNATTENDED PROVIDERS; INTERACTIVE OAUTHCLIENTPROVIDER 6.5 UI:R)- Exploited in Australia?
- unknown
- Patch to
- Upgrade mcp to 1.30.0+ or 2.2.0+. Pass issuer= on ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider; clear stored OAuth client registrations once; if a client may have connected to an untrusted MCP server, rotate client secrets and revoke tokens at the authorization server. On older versions, connect OAuth-enabled clients only to MCP servers you trust.
Primary: GitHub Advisory GHSA-qx49-fqc8-xw99 — MCP Python SDK OAuth credential redirection (28 Sep 2026) · Vendor: Cycode — MCP SDK OAuth flaw / account takeover write-up (28 Sep 2026) · The Hacker News — Official MCP Python SDK OAuth credential theft (29 Sep 2026)
