Trust & Security
Anthropic’s Official MCP Python SDK Had an OAuth Credential-Stealing Flaw That Let Any Malicious Server Hijack Your Login
Missing issuer validation in the official agent communication protocol SDK means every enterprise MCP client using OAuth was exposed. No CVE assigned. The fix requires more than an upgrade.
◆ Heath Callahan