[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#OAuth Credential Theft

articleHIGH 8.0

Anthropic MCP Python SDK Vulnerability: OAuth Credential Theft and Account Takeover

A high-severity vulnerability in Anthropic's Model Context Protocol (MCP) Python SDK could allow a malicious MCP server to steal OAuth credentials, potentially taking over user accounts. The vulnerability affects MCP client deployments using HTTP transport, specifically SDK releases from versions 1.9.1 to 2.1.1. Organizations are advised to update to a patched version immediately. Failure to do so may result in unauthorized account access and data breaches.

Sep 29, 20261 source