Critical MCP Python SDK flaw exposes OAuth credentials to malicious servers
A vulnerability in the official MCP Python SDK allows malicious servers to steal OAuth credentials, including client secrets and PKCE keys, from affected clients.
Daily coverage of AI, developer tools and infrastructure. Each story explains what happened and why it matters, with a link to the original source.
A vulnerability in the official MCP Python SDK allows malicious servers to steal OAuth credentials, including client secrets and PKCE keys, from affected clients.