MCP Python SDK: malicious servers could steal OAuth credentials
Cycode found the official MCP Python SDK (1.9.1–1.29.1 / 2.0.0–2.1.1) could skip issuer checks on OAuth discovery fallbacks, letting a malicious MCP server harvest client secrets, auth codes, and PKCE keys (GHSA-qx49-fqc8-xw99, CVSS 7.5). Fixed in 1.30.0 / 2.2.0—machine-to-machine providers also need an explicit issuer= argument.