A newly disclosed high-severity OAuth vulnerability in Anthropic’s official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal authentication material and take over user accounts This article explores oauth vulnerability anthropic. . The flaw affects HTTP-based MCP clients using vulnerable SDK releases and OAuth providers, enabling attackers to obtain client secrets, authorization codes, and PKCE proof keys.
Attackers can provide metadata claiming to come from legitimate identity providers like Okta, Google, or Microsoft Entra ID, while specifying an attacker-controlled token endpoint. However, instead of sending the code to the legitimate provider's token endpoint, the vulnerable client forwards the code, OAuth client secret, and PKCE code_verifier to infrastructure controlled by the attacker.
Versions 1.9.1 through 1.29.1 failed to validate issuers and bind credentials across discovery paths, leaving gaps in fallback and 403 step-up authentication flows. A stolen OAuth client secret could be reused until rotated, while attackers could gain access to cloud services, internal APIs, databases, deployment pipelines, or other resources via compromised clients. Organizations should upgrade immediately, clear any outdated OAuth client registrations from older releases, and rotate client secrets and revoke tokens if an affected client may have connected to an untrusted MCP server.
Deployments using ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider also need to explicitly configure the expected issuer value; upgrading alone is not sufficient to secure these flows. Explore for your team.










