Pushpak Chhajed from the Laravel team just shared two new security advisories, one for the Laravel AI SDK and one for Laravel MCP. Both issues are fixed, and if either package runs in production, you should update today:
composer update laravel/ai laravel/mcp
Neither advisory has a CVE ID assigned yet, so a security scanner that relies on CVEs might not flag them.
Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters
The first advisory covers a server-side request forgery (SSRF) bug in laravel/ai 1.0.0. It's rated Moderate, with a CVSS score of 5.3.
The Vercel AI SDK adapter and the AG-UI adapter accept file parts with a URL from the client, and the server fetched that URL without validating it. Someone who can call a chat endpoint built on either adapter could make your server send GET requests to internal addresses, such as cloud metadata services, localhost, or private networks. The response is passed to the model as a file attachment, so it can show up in the model's reply.
You're only affected if your app exposes one of these adapters to untrusted clients. Both adapters first shipped in Laravel AI SDK 1.0, so no 0.x release contains them.
Version 1.0.1 fixes it in #1082. Remote file URLs now go through a guard that:
- Accepts only
httpandhttpsURLs - Blocks loopback, private, link-local, CGNAT, reserved, and NAT64-embedded addresses
- Checks every redirect hop and pins the connection to the addresses it checked, which prevents DNS rebinding
If you can't upgrade right away, the advisory suggests removing or rejecting URL-based file parts from incoming chat requests before they reach the adapter. You can also block your server's outbound traffic to internal and metadata addresses.
Hussam Abdulfatah reported the issue, and Pushpak wrote the fix.
Laravel MCP: OAuth Redirect Validation
The second advisory covers how Laravel MCP validated the OAuth redirect URL. It's rated Low.
An attacker could send an authenticated user to an unintended destination during the OAuth flow. Under certain configurations, an attacker who gets a user to follow a crafted link could obtain OAuth data such as authorization codes or tokens and use it to take over that user's account. It needs user interaction, and whether you're affected depends on how your app is configured.
The fix is in versions 0.9.6 and 1.0.1. Bruno Meilick reported the issue.
Affected Versions
| Package | Affected | Fixed |
|---|---|---|
laravel/ai |
1.0.0 | 1.0.1 |
laravel/mcp |
Below 0.9.6, and 1.0.0 | 0.9.6 or 1.0.1 |
For complete details, see the Laravel AI SDK advisory and the Laravel MCP advisory on GitHub, and happy updating!