MCP Python SDK Flaw Lets Malicious Servers Hijack OAuth Tokens and Take Over AI Agent Accounts
A critical security defect has been discovered in the official Model Context Protocol (MCP) Python SDK, which could enable hostile MCP servers to snatch OAuth credentials and seize control of AI agent accounts.
The problem originates from the SDK’s handling of authentication tokens over plain‑text HTTP connections. When a client app talks to an untrusted MCP server, that server can capture the OAuth data exchanged in the session. Because the SDK fails to rigorously verify the server’s identity, a rogue endpoint can extract the token and later act on the original user’s behalf.
The primary group at risk are developers using the MCP Python SDK to embed AI agents in their applications. The vulnerability specifically impacts HTTP‑based MCP clients that have not added protections such as TLS encryption or server‑certificate pinning. Systems that allow connections to third‑party or experimental MCP servers without proper vetting are particularly exposed.
If exploited, the flaw could result in complete account takeover, unauthorized execution of agent tasks, and leakage of any data the agent processes. Since OAuth tokens typically confer wide‑ranging permissions, an attacker who obtains them could manipulate the AI agent, retrieve confidential outputs, or even issue malicious commands to downstream services.
MCP SDK maintainers have confirmed the issue and said a patched release will be issued shortly. Until then they recommend developers limit MCP traffic to trusted, TLS‑secured endpoints, turn on certificate verification, and avoid using the SDK where server identity cannot be guaranteed. They also suggest rotating any potentially compromised OAuth tokens as a safety measure.
The finding joins an expanding roster of supply‑chain vulnerabilities targeting AI tools and developer libraries. Security analysts warn that as AI services become increasingly modular and distributed, the trustworthiness of underlying SDKs forms a vital defensive layer. Continuous monitoring, swift patch application, and strict network hygiene are expected to remain essential tactics for mitigating comparable threats going forward.
Comments (0)
Be the first to comment.
Join the discussion