Audit your MCP Python SDK exposure for the OAuth credential-theft flaw
The 10-minute versionGrep your agent repos and dependency manifests for the "mcp" Python package. If any client is on versions 1.9.1–1.29.1 or 2.0.0–2.1.1, it's vulnerable to the Cycode-disclosed OAuth issuer-validation flaw. Upgrade to 1.30.0 or 2.2.0 and rotate any client secrets used by affected integrations.
Level upIf you use ClientCredentialsOAuthProvider or PrivateKeyJWTOAuthProvider for machine-to-machine MCP auth, upgrading alone isn't enough — explicitly pass an `issuer=` parameter to bind credentials to the expected authorization server, per the advisory.
