A flaw in the widely used Model Context Protocol SDK could let a rogue server redirect an AI client's login credentials to an attacker.
The Hacker News reports that a malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service. On affected versions, the SDK did not always verify where a server pointed it for login, so a rogue server could redirect the client secret, authorization code and PKCE proof key to a token endpoint the attacker controlled, then use them to request a valid access token. Security firm Cycode reported the issue and demonstrated the full credential theft in a test. The maintainers fixed it in versions 1.30.0 and 2.2.0, and no CVE had been assigned as of September 29.
Why it matters: MCP is becoming the standard way AI agents connect to enterprise systems, and a flaw that lets a rogue server hijack an agent's login credentials undermines the trust that agentic workflows depend on. Enterprises building on MCP should update to the patched SDK versions and review which servers their agents are permitted to connect to.