Identity & AccessA flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins
Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.