MCP Python SDK OAuth flaw enabled account takeover (cycode.com)

🤖 AI Summary
A serious vulnerability has been identified in Anthropic's MCP Python SDK, where a malicious Model Context Protocol (MCP) server can hijack the OAuth login process, leading to full account takeover. The flaw lies in the SDK's reliance on unverified responses from the MCP server, which allows an attacker to trick the SDK into sending login credentials—such as client secrets and authorization codes—directly to the attacker's server instead of the legitimate login provider. This manipulation can occur without raising immediate suspicions because the login page appears authentic, effectively bypassing user scrutiny. This vulnerability is particularly significant for the AI/ML community as it highlights critical weaknesses in OAuth implementations, especially in tool and service integrations that rely on automated authentication flows. Attackers can exploit scenarios like UI automation with AI agents, where user interaction might be eliminated entirely, leading to silent credential theft. With a high-risk rating of 7.5, the implications are dire: attackers not only gain access to user accounts but can also utilize long-lived client secrets to generate valid access tokens, potentially compromising multiple downstream services within enterprise environments. The incident serves as a crucial reminder for developers and organizations to strengthen their OAuth security measures and validate the sources of configuration data rigorously.
Loading comments...
loading comments...