Laravel AI SDK &amp; MCP Security Fixes: Update Now | Mohamed Said        [  ![Mohamed Said](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png)   Mohamed Said Laravel Backend Engineer  ](https://msaied.com) [ Home ](https://msaied.com) [ Projects ](https://msaied.com/projects) [ Articles  ](https://msaied.com/articles) [ Certificates ](https://msaied.com/certificates) [ Contact ](https://msaied.com#contact-section) 

       [  ](https://github.com/EG-Mohamed)       

 [ Home ](https://msaied.com) [ Projects ](https://msaied.com/projects) [ Articles ](https://msaied.com/articles) [ Certificates ](https://msaied.com/certificates) [ Contact ](https://msaied.com#contact-section) 

  [ home ](https://msaied.com)    [ articles ](https://msaied.com/articles)    Laravel AI SDK and Laravel MCP Security Fixes: Update Now        On this page       1. [  Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters ](#laravel-ai-sdk-ssrf-in-the-vercel-and-ag-ui-adapters)
2. [  What went wrong ](#what-went-wrong)
3. [  Who is affected ](#who-is-affected)
4. [  The fix in 1.0.1 ](#the-fix-in-101)
5. [  Laravel MCP: OAuth Redirect Validation ](#laravel-mcp-oauth-redirect-validation)
6. [  What went wrong ](#what-went-wrong-6)
7. [  The fix ](#the-fix)
8. [  Affected Versions at a Glance ](#affected-versions-at-a-glance)
9. [  Key Takeaways ](#key-takeaways)

  ![Laravel AI SDK and Laravel MCP Security Fixes: Update Now](https://cdn.msaied.com/722/fbe8df92faa32e9b9cee984a18bd4411.png)

 [  Laravel ](https://msaied.com/articles?category=laravel) [  AI ](https://msaied.com/articles?category=ai)  #security   #laravel-ai   #laravel-mcp   #ssrf   #oauth   #composer  

 Laravel AI SDK and Laravel MCP Security Fixes: Update Now 
===========================================================

     30 Sep 2026      3 min read    ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)  Mohamed Said  

       Table of contents

  9 sections  

1. [  01   Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters  ](#laravel-ai-sdk-ssrf-in-the-vercel-and-ag-ui-adapters)
2. [  02   What went wrong  ](#what-went-wrong)
3. [  03   Who is affected  ](#who-is-affected)
4. [  04   The fix in 1.0.1  ](#the-fix-in-101)
5. [  05   Laravel MCP: OAuth Redirect Validation  ](#laravel-mcp-oauth-redirect-validation)
6. [  06   What went wrong  ](#what-went-wrong-6)
7. [  07   The fix  ](#the-fix)
8. [  08   Affected Versions at a Glance  ](#affected-versions-at-a-glance)
9. [  09   Key Takeaways  ](#key-takeaways)

       Two security advisories dropped on September 30, 2026 for packages that many Laravel applications now depend on: `laravel/ai` and `laravel/mcp`. Both vulnerabilities are patched, and the fix is a single Composer command away.

```bash
composer update laravel/ai laravel/mcp

```

> **Heads-up:** Neither advisory has a CVE ID assigned yet, so automated scanners that rely solely on CVE databases may not flag these issues. Manual review and updating is the only reliable path right now.

Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters
-----------------------------------------------------

The [advisory (GHSA-6qhr-3g93-pxhw)](https://github.com/laravel/ai/security/advisories/GHSA-6qhr-3g93-pxhw) affects `laravel/ai` 1.0.0 and carries a **CVSS score of 5.3 (Moderate)**.

### What went wrong

Both the Vercel AI SDK adapter and the AG-UI adapter accept file parts that include a client-supplied URL. The server fetched that URL without any validation, making it possible for an attacker who can reach a chat endpoint to force your server to issue GET requests to:

- Cloud metadata services (e.g., `169.254.169.254`)
- Localhost or loopback addresses
- Private or link-local network ranges

Because the fetched content is forwarded to the model as a file attachment, the response can surface directly in the model's reply—potentially leaking internal data.

### Who is affected

Only applications that expose the Vercel or AG-UI adapter to untrusted clients. Both adapters shipped for the first time in Laravel AI SDK 1.0, so no 0.x release is affected.

### The fix in 1.0.1

PR [\#1082](https://github.com/laravel/ai/pull/1082) introduces a URL guard that:

- Accepts only `http` and `https` schemes
- Blocks loopback, private, link-local, CGNAT, reserved, and NAT64-embedded addresses
- Validates every redirect hop and pins the connection to the resolved addresses, preventing DNS rebinding attacks

**Workaround (if you cannot upgrade immediately):** Strip or reject URL-based file parts from incoming chat requests before they reach the adapter, and restrict your server's outbound traffic to internal and metadata address ranges.

Hussam Abdulfatah reported the issue; Pushpak Chhajed wrote the fix.

Laravel MCP: OAuth Redirect Validation
--------------------------------------

The [advisory (GHSA-mx2h-h55v-pm44)](https://github.com/laravel/mcp/security/advisories/GHSA-mx2h-h55v-pm44) affects `laravel/mcp` versions below 0.9.6 and version 1.0.0. It is rated **Low**.

### What went wrong

The OAuth redirect URL was not validated strictly enough. Under certain configurations, an attacker who tricks an authenticated user into following a crafted link could redirect them to an unintended destination during the OAuth flow, potentially capturing authorization codes or tokens and taking over the user's account. Exploitation requires user interaction, and impact depends on application configuration.

### The fix

The issue is resolved in **0.9.6** and **1.0.1**. Bruno Meilick reported the vulnerability.

Affected Versions at a Glance
-----------------------------

| Package | Affected | Fixed | |---|---|---| | `laravel/ai` | 1.0.0 | 1.0.1 | | `laravel/mcp` | &lt; 0.9.6 and 1.0.0 | 0.9.6 or 1.0.1 |

Key Takeaways
-------------

- Run `composer update laravel/ai laravel/mcp` immediately if either package is in production.
- The `laravel/ai` SSRF bug (CVSS 5.3) only affects apps exposing the Vercel or AG-UI adapter to untrusted users.
- The `laravel/mcp` OAuth redirect flaw is Low severity but can lead to account takeover under certain configurations.
- No CVE IDs are assigned yet—do not rely on automated scanners alone.
- DNS rebinding protection is now built into the `laravel/ai` URL guard in 1.0.1.
- If an immediate upgrade is impossible, apply the recommended workarounds and restrict outbound network access.

---

*Source: [Laravel News — Laravel AI SDK and Laravel MCP Security Fixes: Update Now](https://laravel-news.com/laravel-ai-mcp-security-advisories)*

 Found this useful?

          [  ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fmsaied.com%2Farticles%2Flaravel-ai-sdk-and-laravel-mcp-security-fixes-update-now&text=Laravel+AI+SDK+and+Laravel+MCP+Security+Fixes%3A+Update+Now) [  ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fmsaied.com%2Farticles%2Flaravel-ai-sdk-and-laravel-mcp-security-fixes-update-now) 

 Frequently Asked Questions 
----------------------------

  3 questions  

     Q01  Which versions of laravel/ai and laravel/mcp are affected by these security advisories?        laravel/ai 1.0.0 is affected by the SSRF vulnerability; it is fixed in 1.0.1. laravel/mcp versions below 0.9.6 and version 1.0.0 are affected by the OAuth redirect issue; the fix is in 0.9.6 or 1.0.1. 

      Q02  My security scanner did not flag these issues. Am I safe?        Not necessarily. Neither advisory has a CVE ID assigned yet, so scanners that rely solely on CVE databases may miss them. You should update both packages manually regardless of what your scanner reports. 

      Q03  What should I do if I cannot upgrade laravel/ai to 1.0.1 right away?        As a temporary workaround, remove or reject URL-based file parts from incoming chat requests before they reach the Vercel or AG-UI adapter, and restrict your server's outbound traffic to internal and cloud metadata address ranges. 

  Continue reading

 More Articles 
---------------

 [ View all    ](https://msaied.com/articles) 

 [ ![PostgreSQL Recursive CTEs in Laravel: Hierarchical Data Without the ORM Gymnastics](https://cdn.msaied.com/720/3e3d256d54dd4036099122e0b035e482.png) laravel postgresql eloquent 

### PostgreSQL Recursive CTEs in Laravel: Hierarchical Data Without the ORM Gymnastics

Recursive CTEs let PostgreSQL walk tree structures in a single query. Learn how to wire them into Laravel's qu...

  ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)  Mohamed Said 

 30 Sep 2026     2 min read  

  Read    

 ](https://msaied.com/articles/postgresql-recursive-ctes-in-laravel-hierarchical-data-without-the-orm-gymnastics) [ ![FrankenPHP, OPcache JIT, and Preloading: Maximising Laravel Throughput](https://cdn.msaied.com/719/2129727c31378ebd8778814d6764bac1.png) laravel frankenphp performance 

### FrankenPHP, OPcache JIT, and Preloading: Maximising Laravel Throughput

A practical deep-dive into running Laravel under FrankenPHP with OPcache JIT and preloading enabled — covering...

  ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)  Mohamed Said 

 30 Sep 2026     2 min read  

  Read    

 ](https://msaied.com/articles/frankenphp-opcache-jit-and-preloading-maximising-laravel-throughput-1) [ ![What's New in Laravel 13.34: Worker Crash Tracking, Timeout Signals, and More](https://cdn.msaied.com/721/fce528b9143188e98a1629bc9d8f17b2.png) Laravel Queue Laravel 13 

### What's New in Laravel 13.34: Worker Crash Tracking, Timeout Signals, and More

Laravel 13.34 ships opt-in worker crash counting toward maxExceptions, SIGALRM notifications for interruptible...

  ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)  Mohamed Said 

 30 Sep 2026     3 min read  

  Read    

 ](https://msaied.com/articles/whats-new-in-laravel-1334-worker-crash-tracking-timeout-signals-and-more) 

   [  ![Mohamed Said](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png)   Mohamed Said Laravel Backend Engineer  ](https://msaied.com)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

Explore

- [Home](https://msaied.com)
- [Projects](https://msaied.com/projects)
- [Articles](https://msaied.com/articles)
- [Certificates](https://msaied.com/certificates)
- [Contact](https://msaied.com#contact-section)

Connect

- [   hello@msaied.com ](mailto:hello@msaied.com)
- [   +20 109 461 9204 ](tel:+201094619204)

© 2026 Mohamed Said. All rights reserved.

 [  ](https://github.com/EG-Mohamed) [  ](https://www.linkedin.com/in/msaiedm/) [  ](https://wa.me/201094619204) [  ](mailto:hello@msaied.com) [  ](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
