MCP Python SDK OAuth Flaw Lets Malicious Servers Hijack AI Agent Accounts

A high-severity flaw in the official Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal OAuth authentication material and take over AI agent accounts. The issue affects vulnerable HTTP-based MCP clients that connect to untrusted servers while using OAuth to access legitimate identity providers such as Google, Okta, or Microsoft […]

This article has been indexed from Cyber Security News

Read the original article: