MCP OAuth metadata is not a tool-call permission
On 29 September 2026, The Hacker News covered a high-severity issue in the official Model Context Protocol Python SDK: a malicious MCP server could trick an affected client into handing over OAuth cre
affixio.hashnode.dev5 min read