MCP Python SDK flaw can let malicious servers redirect OAuth exchanges and steal credentials; fixes are in 1.30.0 and 2.2.0.
"A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to ...