跳到主要內容

MCP Python SDK漏洞評測:OAuth憑證恐遭惡意伺服器竊取 | MCP Python SDK Review: OAuth Flaw Risked Credential Theft

By Kit 小克 | AI Tool Observer | 2026-10-01

🇹🇼 MCP Python SDK漏洞評測:OAuth憑證恐遭惡意伺服器竊取

MCP Python SDK爆OAuth漏洞:惡意伺服器能整碗端走你的登入憑證

如果你的AI agent或MCP client是用官方MCP Python SDK連線遠端伺服器,現在該檢查版本號了。GitHub在2026年9月28日發布安全公告GHSA-qx49-fqc8-xw99,指出MCP Python SDK的OAuth用戶端實作有一個CVSS 7.5分的高風險漏洞,只要接上一台惡意或已被入侵的MCP伺服器,你的OAuth憑證可能整組被偷走。

漏洞怎麼運作

問題出在SDK做OAuth discovery(自動探測授權伺服器設定)時,沒有在每一條路徑上驗證issuer身分,也沒把已儲存或預先配置的client憑證跟真正的授權伺服器綁定。攻擊手法很簡單:惡意MCP伺服器故意對標準的discovery請求回傳404,逼SDK改成直接向該伺服器索取OAuth設定——而這台伺服器當然可以自己指定token endpoint網址。結果就是你的client_secret、authorization code、PKCE code_verifier三樣東西,全部乖乖送到攻擊者手上。攻擊者拿到這些之後,可以向真正的登入服務換到一張合法的access token,權限跟你的app被授權的一樣大。

誰會中招、怎麼修

受影響版本是1.x的1.9.1到1.29.1,以及2.x的2.0.0a1到2.1.1。只要你的程式用SDK當MCP client、透過HTTP連線,並且用了OAuthClientProvider、ClientCredentialsOAuthProvider、PrivateKeyJWTOAuthProvider或舊版的RFC7523OAuthClientProvider做驗證,同時會連到不是100%信任的MCP伺服器,就在風險名單裡。修法很直接:升級到1.30.0或2.2.0,兩個版本都已經修掉這個issuer驗證漏洞。

這件事對正在瘋狂串接MCP工具鏈的團隊是個提醒:MCP生態圈擴張得比安全稽核快,agent一多、串接的第三方伺服器一多,攻擊面就跟著變大。如果你手上有內部工具或agent框架接了MCP client功能,這次不是選擇性更新,是該馬上排進本週的維護清單。

好不好用,試了才知道。


🇺🇸 MCP Python SDK Review: OAuth Flaw Risked Credential Theft

MCP Python SDK Review: OAuth Flaw Let Rogue Servers Steal Your Credentials

If your AI agent stack uses the official MCP Python SDK to connect to remote Model Context Protocol servers, check your version now. On September 28, 2026, GitHub published security advisory GHSA-qx49-fqc8-xw99 disclosing a CVSS 7.5 vulnerability: connect to a malicious or compromised MCP server, and it can walk away with your OAuth credentials.

How the Attack Works

The bug lives in OAuth discovery. The SDK didn't validate the authorization server's issuer identity on every discovery path, and it didn't bind stored or pre-provisioned client credentials to the authorization server they actually belong to. The exploit is almost boring in its simplicity: a malicious MCP server returns a 404 on the standard discovery request, which forces the client to fetch OAuth configuration directly from that server instead — meaning the attacker gets to name their own token endpoint. The client then hands over its client_secret, authorization code, and PKCE code_verifier to whoever controls that endpoint. With those three pieces, an attacker can redeem a real access token from the legitimate identity provider, inheriting whatever permissions your app was granted.

Who's Affected and the Fix

Affected versions span 1.9.1 through 1.29.1 on the 1.x line, and 2.0.0a1 through 2.1.1 on 2.x. You are at risk if you use the SDK as an MCP client over HTTP with OAuthClientProvider, ClientCredentialsOAuthProvider, PrivateKeyJWTOAuthProvider, or the deprecated RFC7523OAuthClientProvider — and you connect to any MCP server you do not fully trust. The fix is straightforward: upgrade to 1.30.0 or 2.2.0, both of which patch the issuer validation gap.

The bigger lesson: MCP adoption is outrunning security review. As more teams wire agents into third-party MCP servers, the attack surface grows faster than anyone is auditing it. If you have internal tools or agent frameworks using MCP client auth, this is not a nice-to-have patch — put it on this week's maintenance list.

好不好用,試了才知道。

Sources / 資料來源

延伸閱讀 / Related Articles


AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends

留言

這個網誌中的熱門文章

Google Ironwood TPU v7 推理專用晶片解析:效能追平 NVIDIA、成本低 44%,AI 晶片戰爭正式開打 | Google Ironwood TPU v7 Explained: Matching NVIDIA Performance at 44% Lower Cost — The AI Chip War Heats Up

Claude Code 實測:AI 幫你寫程式到底行不行? | Claude Code Review: Can AI Really Code for You?

Cursor vs GitHub Copilot vs Claude Code:AI 程式助手大比拼 | AI Coding Assistants Compared: Cursor vs GitHub Copilot vs Claude Code