Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
More info
