Anthropic MCP Python SDK Vulnerability Allows OAuth Credential Stealing
2026-09-30 15:21:15
According to CoinMeta, as reported by Forkast, there is a credential theft vulnerability in the official MCP Python SDK of Anthropic that allows any malicious server to hijack user logins. This vulnerability was disclosed on September 28th and has been assigned the tracking number GHSA-QX49-FQC8-XW99; its severity score is 7.5 on the vulnerability rating scale. Security company Cycode demonstrated a complete attack chain, showing that the stolen credentials are sufficient to obtain valid access tokens from legitimate identity providers. Affected versions of SDK fail to verify the address of the authorized server during authentication, allowing attackers to exploit this weakness. Fixes for this issue are available in versions 1.30.0 and 2.2.0; after upgrading, organizations should clear any stored OAuth client credentials and rotate the client keys.
Source:Forkast
This content is for market information only and does not constitute investment advice.
Follow HKWDB official accounts to stay updated

Hot Articles
Refresh

Bitcoin October 2026 Outlook: Can the 19% Historical Gain Hold?
5h ago

Dogecoin Price: Whales Buy $112M, Can DOGE Break $0.10?
09-29 12:48

What is Solidigm? Is Its $150B IPO Valuation a Bubble?
09-28 13:00

Is PAXG Stable? Is Gold-Backed Better Than Stablecoins?
09-24 18:04

ETH Rebounds to $2,800: Can It Hold $3,200 by Month-End?
09-23 11:07



