{"schema":"hottub-news/story/v1","story":"st_6g7rqf46ne6htqdvvjwq","title":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials","title_en":null,"outlets":1,"brief":null,"page":"https://hottub.news/stories/official-mcp-python-sdk-flaw-can-let-malicious-servers-steal-oauth-6g7rqf46ne","count":1,"items":[{"id":"n_6g7rqf46ne6htqdvvjwq","seq":599862,"kind":"article","title":"Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials","url":"https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html","summary":"A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and","published":"2026-09-29T06:08:25Z","seen":"2026-09-29T07:00:27Z","lang":"en","source":{"id":"kite-feedburner-com-5fa171","name":"feedburner.com","domain":"feeds.feedburner.com"},"via":"kite-feedburner-com-5fa171","topics":["cybersecurity"],"authors":["author"],"entities":[{"id":"Q6895932","name":"Molecular & Cellular Proteomics","type":"org"},{"id":"Q743238","name":"OAuth","type":"other"}],"image":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2N5owhsoQXHTQV74afwfngdyitjwcW37BHLX2QKkq6xZAxP8_AOXAh1ODPj5DyvvmMUq3mKH9eR2B1r7owc6djzLViK2U4BY_hw3rTWmaHjhFEyyh8LPlUMPZ7MdWkqN7bjtQyMByBLrsI5m0mAU9y-IbrsAe9OPhZXHN63AWwuv_1OB5MSrpRdVZ9CM/s1600/mcp-python.jpg","mentions":2,"story":"st_6g7rqf46ne6htqdvvjwq","category":"science-technology","category_p":0.6100000143051147,"sentiment":"negative","tone":-0.5600000023841858,"political":0.10999999940395355}]}