MCP Python SDK flaw lets malicious servers steal OAuth credentials
The official MCP Python SDK (1.9.1–1.29.1 and 2.0.0–2.1.1) could send client secrets, auth codes, and PKCE keys to an attacker-controlled token endpoint when connecting over HTTP OAuth. Fix is 1.30.0 / 2.2.0; ClientCredentials and PrivateKeyJWT users must also set issuer=, clear stored registrations, and rotate secrets if they connected to untrusted servers.