Critical Vulnerability in MCP Python SDK Exposes AI Agent Accounts to OAuth Hijacking
A severe security weakness has been identified in the official Model Context Protocol (MCP) Python software development kit, potentially allowing hostile MCP servers to capture OAuth credentials and assume control of AI agent accounts.
The flaw stems from the way the SDK handles authentication tokens when communicating over unsecured HTTP connections. If a client application connects to an MCP server that is not trusted, the server can intercept the OAuth material exchanged during the session. Because the SDK does not enforce strict validation of the server’s identity, a malicious endpoint can retrieve the token and reuse it to act on behalf of the original user.
Developers who rely on the MCP Python SDK for integrating AI agents into their services are the primary audience at risk. The vulnerability specifically targets HTTP‑based MCP clients that have not implemented additional safeguards such as TLS encryption or server certificate pinning. Environments that permit connections to third‑party or experimental MCP servers without proper vetting are especially vulnerable.
Exploitation of the issue could lead to full account takeover, unauthorized execution of agent tasks, and exposure of any data the agent processes. Since OAuth tokens often grant broad permissions, an attacker who captures them could manipulate the AI agent, retrieve confidential outputs, or even propagate malicious instructions to downstream systems.
The maintainers of the MCP SDK have acknowledged the problem and indicated that a patched version will be released promptly. In the meantime, they advise developers to restrict MCP communications to trusted, TLS‑encrypted endpoints, enable certificate verification, and avoid using the SDK in contexts where the server identity cannot be assured. Organizations are also encouraged to rotate any potentially compromised OAuth tokens as a precaution.
This discovery adds to a growing list of supply‑chain‑related vulnerabilities affecting AI tooling and developer libraries. Security experts note that as AI services become more modular and distributed, the integrity of the underlying SDKs becomes a critical line of defense. Ongoing monitoring, rapid patch deployment, and rigorous network hygiene are likely to remain key strategies for mitigating similar risks in the future.
Comments (0)
Be the first to comment.
Join the discussion