TGViewer
Linuxgram 🐧 Linuxgram 🐧 @linuxgram · 72.7K subscribers
Post #20516 1.11K
📰 Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory.Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and.

🔗 Source: https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html

#python
  • 👍 5
More from @linuxgram
  1. Oct 1, 2026📰 Minecraft Dungeons II doesn't seem to run on SteamOS / Linux Minecraft Dungeons II is a…
  2. Oct 1, 2026📰 Emmabuntüs Debian Edition 1.03 Adds New Accessibility Features, Debian 13.7 Base Emmabu…
  3. Oct 1, 2026📰 ACE COMBAT 8: WINGS OF THEVE shows online play not working on SteamOS / Linux ACE COMBA…
  4. Oct 1, 2026📰 qBittorrent 5.2.4 Open-Source BitTorrent Client Released with WebUI Improvements qBitto…
  5. Oct 1, 2026📰 NVIDIA Developing "Display Config Server" To Improve Linux/Wayland On Display Walls As…
  6. Oct 1, 2026📰 Dutch government turns to NixOS for a sovereign desktop DAWO combines a Linux-based cli…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →