What the flaw is
The Model Context Protocol defines how AI agents communicate with tool servers. The Python SDK implements an OAuth 2.0 flow that agents use to authenticate to MCP servers. Cleafy's research team identified a logic error in how the SDK validates the redirect URI during the authorization code exchange. A malicious MCP server can manipulate the handshake so that the access token issued at the end of the flow is forwarded to an attacker-controlled endpoint instead of being stored by the agent. The agent completes the flow and continues operating, unaware that its credential has been exfiltrated.
The attack surface
The flaw is exploitable by any MCP server that an agent is configured to connect to. In a typical agentic deployment, a single agent connects to multiple MCP servers, often including community-published packages from public registries. If any one of those servers is malicious or has been compromised, it can use this flaw to steal the agent's OAuth tokens for any service the agent is authorized to access, including cloud provider APIs, database connectors, and internal REST services. The breadth of damage depends on what scopes those tokens carry.
Affected versions and what to do
The flaw affects mcp[cli] versions prior to 1.9.4. The fix validates the redirect URI against the registered client configuration before completing the token exchange. Update with pip install --upgrade mcp. After updating, review your identity provider's token issuance logs for MCP server connections established during the vulnerable window and revoke any tokens that cannot be accounted for. If your agents run with broad OAuth scopes, treat this as a credential-rotation event.
Broader implications for agentic security
This flaw illustrates a structural risk in the MCP ecosystem: agents are expected to connect to arbitrary third-party servers, and the security of the agent's credential store depends on every server in that list behaving correctly. Security teams deploying AI agents should maintain an explicit allowlist of permitted MCP servers, enforce hash-pinning or code signing for server packages, and treat MCP server connections with the same scrutiny applied to third-party API integrations. Credential isolation, where each MCP server connection uses a token scoped only to the resources that server legitimately requires, limits the damage when a server is compromised.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are hardening the credential architecture of your agentic AI environment.