The Hacker News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

بقلم The Hacker News

1 دقيقة قراءة
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

هل لديك أخبار لمشاركتها مع صناعة الفعاليات؟

أرسل بياناً صحفياً أو تلميحاً بقصة وتواصل مع آلاف المهنيين في مجال الفعاليات.

تواصل معنا→

المزيد في Cybersecurity, Cryptography & Digital Trust

رؤى ذات صلة