Executive Summary
A critical security vulnerability in the official Model Context Protocol (MCP) Python SDK allowed malicious servers to steal OAuth credentials from AI applications. The flaw, rated 7.5 CVSS, enabled attackers to redirect authentication flows to attacker-controlled endpoints, capturing client secrets, authorization codes, and PKCE proof keys. Applications using versions 1.9.1 through 1.29.1 and 2.0.0 through 2.1.1 were vulnerable when connecting to untrusted MCP servers over HTTP with OAuth providers.
This incident highlights the growing security risks in AI supply chains as organizations rapidly adopt AI integration frameworks. With AI applications increasingly connecting to external services and data sources, vulnerabilities in foundational SDKs can expose sensitive authentication credentials across entire AI ecosystems, making supply chain security paramount for AI adoption.
Why This Matters Now
AI supply chain attacks are escalating as organizations rush to integrate AI capabilities without proper security vetting. This MCP SDK flaw demonstrates how vulnerabilities in foundational AI frameworks can compromise authentication across multiple applications simultaneously.
Attack Path Analysis
Attackers exploited the MCP Python SDK OAuth vulnerability to steal credentials during client-server authentication, potentially escalating privileges through compromised tokens, moving laterally across connected services, establishing persistent access through long-lived client secrets, exfiltrating OAuth tokens and sensitive data from integrated services, and ultimately achieving account takeover with full permissions of the compromised application.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Malicious MCP server exploits OAuth credential theft vulnerability (GHSA-qx49-fqc8-xw99) in Python SDK versions 1.9.1-1.29.1 and 2.0.0-2.1.1 by redirecting client authentication to attacker-controlled authorization server
Related CVEs
CVE-2024-45590
CVSS 7.5OAuth credential exposure vulnerability in MCP Python SDK allows malicious servers to steal client secrets and authorization codes through token endpoint manipulation.
Affected Products:
Model Context Protocol MCP Python SDK – 1.9.1 through 1.29.1, 2.0.0 through 2.1.1
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Trusted Relationship
Steal Application Access Token
Use Alternate Authentication Material: Application Access Token
Forge Web Credentials: SAML Tokens
Valid Accounts: Cloud Accounts
Supply Chain Compromise: Compromise Software Supply Chain
Process Injection: Process Hollowing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication Controls
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – ICT Third-Party Risk Management
Control ID: Article 9
CISA ZTMM 2.0 – Identity and Access Management
Control ID: ID.AM-6
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001 – Information Security Policy for Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical supply-chain vulnerability in MCP Python SDK enables OAuth credential theft, threatening AI application security and requiring immediate SDK upgrades across development pipelines.
Information Technology/IT
MCP SDK flaw exposes IT infrastructure to credential compromise through malicious servers, demanding enhanced zero-trust segmentation and egress security controls for protection.
Financial Services
OAuth token theft vulnerability threatens financial API integrations and customer data access, requiring immediate compliance remediation under PCI and regulatory frameworks.
Health Care / Life Sciences
Supply-chain attack vector compromises healthcare AI systems' OAuth authentication, risking HIPAA violations and patient data exposure through credential theft mechanisms.
Sources
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentialshttps://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.htmlVerified
- MCP Python SDK OAuth Credential Exposure Advisoryhttps://github.com/modelcontextprotocol/python-sdk/security/advisories/GHSA-qx49-fqc8-xw99Verified
- MCP Python SDK OAuth Account Takeover Researchhttps://cycode.com/blog/mcp-python-sdk-oauth-account-takeover/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this MCP OAuth vulnerability by constraining lateral movement through segmented access controls and limiting data exfiltration through controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network-level segmentation could limit the attacker's ability to establish unauthorized connections between the compromised MCP client and malicious OAuth servers outside trusted network boundaries
Control: Zero Trust Segmentation
Mitigation: Identity-aware segmentation may limit the scope of permissions and services accessible even with compromised OAuth tokens, reducing the effective privilege escalation across cloud workloads
Control: East-West Traffic Security
Mitigation: Microsegmentation controls would likely restrict the attacker's ability to move between services and cloud workloads, limiting access to only explicitly authorized service-to-service communication paths
Control: Multicloud Visibility & Control
Mitigation: Enhanced visibility into cross-cloud API communications may enable detection of anomalous patterns and provide controls to limit persistent access across multiple cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely limit the attacker's ability to exfiltrate data by restricting outbound data flows and enforcing inspection of API-based data transfers
While complete account compromise may still occur, the blast radius would likely be significantly reduced through segmented workload isolation and constrained service-to-service access permissions
Impact at a Glance
Affected Business Functions
- AI Application Development
- API Authentication Services
- OAuth Token Management
- Third-Party Integrations
Estimated downtime: 2 days
Estimated loss: N/A
OAuth client secrets, authorization codes, and PKCE proof keys exposed to malicious MCP servers, potentially allowing unauthorized access to connected services with whatever permissions the compromised applications were granted.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit OAuth token scope and prevent lateral movement across services
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration through compromised application credentials
- • Enable Multicloud Visibility & Control to monitor anomalous OAuth token usage patterns and suspicious API interactions
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal application behavior and alert on credential abuse
- • Establish Cloud Native Security Fabric (CNSF) controls for real-time inspection of AI application interactions and OAuth flow validation



