interesting · Research — edge
MCP Python servers can accept a bearer token minted for another service behind the same authorization server.
Affects
The Model Context Protocol Python SDK, used to build HTTP-accessible MCP servers.
A caller with a valid sibling-service token can authenticate to an affected MCP HTTP server when the verifier does not enforce the receiving resource as the token audience.
Detail and 1 source
The repair is incomplete by default: upgrading adds resource validation but leaves it disabled until the operator configures it.