Researchers Found Critical Vulnerability in Anthropic SDK

A security flaw in the Model Context Protocol Python SDK could allow attackers to compromise user accounts.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of a brass padlock clamped onto a segmented fiber optic cable, representing a digital security vulnerability.
Security researchers identified a high-severity vulnerability in the Anthropic Model Context Protocol Python SDK that risks unauthorized access to user credentials. AI Illustration. Upload story photo >

Live Poll

Do you feel software vulnerabilities are making your personal online accounts less secure than before?

Security researchers have identified a high-severity vulnerability affecting the Anthropic Model Context Protocol (MCP) Python SDK. This flaw specifically impacts client deployments utilizing HTTP transport, enabling malicious servers to extract OAuth credentials and gain unauthorized account access.

Why it matters

As development teams increasingly adopt the Model Context Protocol to bridge AI models with external data sources, this vulnerability underscores the security risks inherent in automated authentication flows. The oversight highlights the necessity of strictly vetting server-side connections in evolving LLM-integrated ecosystems.

The vulnerability persists in Anthropic MCP Python SDK versions 1.9.1 through 2.1.1. It specifically enables unauthorized credential exfiltration within HTTP transport configurations.

The players

Anthropic

An AI safety and research company that develops the Claude large language model and associated developer frameworks like the Model Context Protocol.

The details

The security flaw functions by allowing a malicious MCP server—a component that provides external data to an AI model—to intercept sensitive OAuth tokens. When a user connects to a compromised server via the SDK, the underlying HTTP transport logic fails to verify the source, granting the attacker unauthorized access to account credentials. This creates a bridge for identity theft within the Model Context Protocol, an open standard for connecting AI assistants to data systems.

Timeline

  1. September 29, 2026: Security researchers disclosed the MCP SDK vulnerability.

The Tech Race

The vulnerability affects the security of the Model Context Protocol, following a pattern of early-stage protocol hardening seen in nascent communication standards. This discovery marks a critical security milestone for the Model Context Protocol as it matures from a research-led standard to a production-level integration tool.

Developers using Anthropic SDK versions 1.9.1 through 2.1.1 in production environments should audit their HTTP transport configurations immediately. Organizations should verify whether their current MCP server integrations are susceptible to credential extraction while awaiting further guidance.

The takeaway

The incident serves as a reminder to limit data permissions when using new AI protocols that connect to sensitive external credentials. Developers should monitor the official repository for version updates that patch the HTTP transport logic.

Further reading

For broader trends in secure AI integration, visit our Cybersecurity section.

Source note: This article includes information reported by IT Security News - cybersecurity, infosecurity news.

Live Poll

Do you feel software vulnerabilities are making your personal online accounts less secure than before?