On September 30, 2026, Laravel team member Pushpak Chhajed published two GitHub security advisories. The issues affect laravel/ai and laravel/mcp, and neither advisory has a CVE identifier. CVE-based scanners may therefore fail to report them.
composer update laravel/ai laravel/mcpThe laravel/ai advisory covers an SSRF vulnerability in version 1.0.0. Its Vercel AI SDK and AG-UI adapters accepted file parts containing client-supplied URLs, then fetched those URLs on the server. A caller of an exposed chat endpoint could steer the server toward internal targets, such as cloud metadata services or private networks. The fetched response was supplied to the model as a file attachment and could appear in its reply.
The issue only affects applications that expose one of these adapters to untrusted clients. Both adapters were introduced in Laravel AI SDK 1.0, so 0.x releases are not affected. Version 1.0.1 fixes the problem in pull request #1082. The new protection permits only http and https URLs, blocks loopback, private, link-local, CGNAT, reserved, and NAT64-embedded addresses, and validates every redirect hop. It also pins the connection to the checked addresses to prevent DNS rebinding. Hussam Abdulfatah reported the issue, and Pushpak Chhajed prepared the fix.
The Laravel MCP advisory concerns OAuth redirect validation and is rated Low. In affected configurations, an attacker could use a crafted link to send an authenticated user to an unintended destination. With user interaction, the flow could expose authorization codes or tokens and enable account takeover. The fix is available in versions 0.9.6 and 1.0.1. Bruno Meilick reported the vulnerability.
Affected laravel/mcp versions are all releases below 0.9.6 and version 1.0.0. If an immediate upgrade is not possible, applications using the AI adapters should reject URL-based file parts before they reach the adapter. Restricting outbound connections to internal and metadata addresses is an additional mitigation.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.