29 Sept 2026
MCP Python SDK clients could hand OAuth secrets to a hostile server: upgrade to 1.30.0 or 2.2.0 and set the issuer
A high-severity advisory in the official MCP Python SDK lets a malicious MCP server steer a client’s OAuth secret, code and PKCE verifier…