MCP Python SDK maintainers rated a flaw that let a connected server choose where OAuth secrets were sent High, at 7.5. For its two machine-to-machine providers, upgrading changes nothing until the client names the issuer it expects.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence50
MCP Python SDK releases 1.30.0 and 2.2.0 leave a credential-theft bug open for two OAuth providers unless their constructors pass an issuer. For unattended MCP clients the fix is a one-argument code change, and each team has to find and make it in its own source.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
MCP Python SDK maintainers fixed a flaw rated up to 7.5 that lets malicious servers steal OAuth client secrets, in versions 1.30.0 and 2.2.0. Two of the affected providers stay exposed after upgrading until the calling code passes issuer=.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives30
- Confidence70
A consultancy's account of production MCP work on Django client apps calls the protocol a transport layer. Its sample server calls django.setup(), imports the Order model, and dispatches tool calls on a string.
Reality
- Evidence60
- Adoption25
- Hype gap+12
- Incentives55
- Confidence55
Mike Moore's harness shows MCP's server-authored instructions field placing hostile prose in an agent's context, and a caching proxy passing it to a second caller. The harness measures where the text lands, with no model in the loop.
Reality
- Evidence68
- Adoption58
- Hype gap+8
- Incentives45
- Confidence66
The Python SDK's v2.0.0 moved mcp.server.fastmcp wholesale on July 28 and shipped no shim, so any project that wrote mcp>=1.0 pulls 2.x on the next fresh install. A second default quietly changed the name clients see.
Reality
- Evidence62
- Adoption28
- Hype gap+18
- Incentives58
- Confidence57
The MCP Python SDK renamed FastMCP in 2.x. Gemini's Interactions API stopped accepting the schema google-genai 1.x sends. Both arrived on a fresh install of unchanged code, and the mocked unit tests never noticed.
Reality
- Evidence74
- Adoption28
- Hype gap+8
- Incentives40
- Confidence68
The official mcp package hit 2.0.0 on 28 July with renamed imports and a shorter context-manager yield, so wrappers that declared no upper bound now fail at runtime on a fresh install of code nobody touched.
Reality
- Evidence62
- Adoption45
- Hype gap+6
- Incentives30
- Confidence58
An AWS EC2 rig with mcp unbounded in requirements.txt picked up mcp 2.2.0 and stopped importing. The server edit is two lines; the pip resolver and the test suite's camelCase attribute reads are where the work sits.
Reality
- Evidence72
- Adoption30
- Hype gap−8
- Incentives35
- Confidence68
A duplicate method name raises ValueError while MCPServer is being constructed. That puts the failure inside whatever code assembles your extensions, and it is why a collision test cannot live in either extension's own package.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives25
- Confidence56
A standing measurement of 14 MCP servers finds Claude's tokenizer counts schema text a median 64.1 percent above tiktoken, the counter every published cost study uses.
Reality
- Evidence62
- Adoption28
- Hype gap−8
- Incentives45
- Confidence55