Skip to finding
interesting · Research — edge

MCP Python servers can accept a bearer token minted for another service behind the same authorization server.

Affects

The Model Context Protocol Python SDK, used to build HTTP-accessible MCP servers.

A caller with a valid sibling-service token can authenticate to an affected MCP HTTP server when the verifier does not enforce the receiving resource as the token audience.

Detail and 1 source

The repair is incomplete by default: upgrading adds resource validation but leaves it disabled until the operator configures it.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, October 6, 2026