The Hacker News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and

作者 The Hacker News

1 分钟阅读
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

有活动行业的新闻要分享吗?

提交新闻稿或信息,触达数千名活动行业专业人士。

联系我们→

更多Cybersecurity, Cryptography & Digital Trust相关内容

相关洞察