decrypted · 29 september 2026 · vulnerabilities and patching · supply chain · ai and llm security
An MCP flaw lets a rogue tool server steal an AI agent's login keys
On Monday the maintainers of the official Model Context Protocol Python SDK published an advisory for a flaw that lets a malicious tool server quietly collect the keys an AI agent uses to log in elsewhere. The SDK is maintained by Anthropic, which is worth saying plainly. The fix shipped on 7 September, but was described only as a behaviour change in the release notes. The advisory and the Cycode write-up followed on 28 September. No exploitation has been reported. For UK organisations wiring agents into mail, code and finance systems, the interesting part is not the bug but the assumption behind it.
What went wrong
MCP is the plug standard that lets an AI assistant use outside tools. When a client connects to a server that needs a login, it must first work out which login service to trust. The SDK asked the server itself. If the server did not support the modern discovery method and returned a 404, the SDK fell back to accepting whatever login configuration the server supplied, without checking that it named the genuine provider.
Think of asking a stranger at the door which bank to pay, then believing the bank they name. Cycode found the SDK did contain safety checks on issuer, credential binding and audience, but on that fallback path they were all fed the same unverified input, so none of them ever fired.
What the attacker gets, and what you see
The prize is the client secret, which is long-lived, plus an authorisation code and the PKCE proof key meant to stop code theft. With those, an attacker can ask the real login service for valid access tokens and act with whatever permissions the application holds. Cycode's words are stark: "The victim has no signal. Nothing in the login flow looks wrong."
There are no failed attempts, odd addresses or MFA prompts, because from the authorisation server's side the authentication is legitimate. The advisory rates the flaw High (7.5) and lists no effective workaround on vulnerable versions beyond connecting only to servers you trust. Affected versions are mcp 1.9.1 to 1.29.1 and 2.0.0 to 2.1.1. Fixed versions are 1.30.0 and 2.2.0.
The steps after upgrading matter as much as the upgrade:
- Clear stored OAuth registrations saved by older versions.
- For unattended providers, pass the issuer explicitly. The advisory says this becomes mandatory in version 3.0.
- If an untrusted server was ever reachable, rotate client secrets and revoke tokens.
The Secure by Design lesson
A client should decide whom to trust from configuration it already holds, never from the party it is trying to authenticate. That is the design decision that would have prevented this: pin the issuer up front and refuse to proceed if the answer differs.
The cost of applying the lesson is small. It is one configuration line per connection, plus something many firms lack: an inventory of which agents exist, which servers they talk to and which long-lived secrets they carry. Third-party MCP servers are a supply chain, and a director should be able to get that list within a day. If it takes a month, the agents are running ahead of the governance.
Also this week
Kiteworks now says why. Having asked customers to shut down over the weekend on federal intelligence of a possible attack, Kiteworks has since said it found and fixed a previously unknown critical flaw in Advanced Forms, used by under 1% of customers. It reports no evidence of exploitation and no CVE has been assigned. Sources differ on how long the shutdown lasted, so I have left the duration out. The design lesson is that a vendor able to warn customers, but unable to say what for, is asking for trust it has not yet earned.
Dutch arrest in the ShinyHunters inquiry. Dutch police confirmed the arrest of a 24-year-old man from Amsterdam on 15 September in an investigation into ShinyHunters, and a Rotterdam court has ordered him held. BleepingComputer reports he was previously sentenced for hacking and extortion, but describes the ShinyHunters link as circumstantial. The group told it he has no association with it. Treat that as a denial from an interested party, and the link as unproven.
101 malicious npm packages. OX Security reports a cluster of 101 packages, downloaded about 490,000 times, that abuse the open-source Baileys WhatsApp library to subscribe developers' authenticated sessions to attacker-controlled groups. It is a nuisance rather than a catastrophe, but it shows a lookalike fork can run with your session. For UK teams, treat a fork of a popular library as a new supplier and vet it accordingly.
Sources
- GitHub Security Advisory: OAuth credential leakage in the MCP Python SDK
- Cycode: MCP Python SDK OAuth account takeover
- The Hacker News: Official MCP Python SDK flaw can let malicious servers steal OAuth credentials
- BleepingComputer: Kiteworks lifts shutdown warning after patching critical flaw
- BleepingComputer: Dutch police confirm arrest in ShinyHunters hacking investigation
- The Hacker News: 101 malicious npm packages abuse Baileys WhatsApp library
If you would like help mapping which AI agents hold which credentials in your organisation, get in touch.
More like this
- An AI agent wiped Azure storage in seven minutes, using a password left on GitHub 28 september 2026
- A wormable DNS flaw headlines Microsoft's biggest Patch Tuesday yet 10 september 2026
- The BGP hijack that slipped a backdoor into a VPS control panel 3 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.