Official MCP Python SDK Let Malicious Servers Steal OAuth Secrets, and Upgrading Isn't Enough
A flaw in the official MCP Python SDK let a hostile MCP server redirect OAuth client secrets. Fixed in 1.30.0 and 2.2.0, but M2M providers also need issuer=.