Laravel AI SDK &amp; MCP Security Fixes: Update Now | Mohamed Said       [Skip to content](#main)  [ ![](https://cdn.msaied.com/01KT78WE565VEMM3PSNQAAB0MH.png) Mohamed SaidLaravel Backend Engineer ](https://www.msaied.com/public) - [Home](https://www.msaied.com/public)
- [Projects](https://www.msaied.com/public/projects)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [About](https://www.msaied.com/public#about)

           [  Contact](https://www.msaied.com/public#contact) Menu 

Menu
----

Close 

 - [HomeStart here](https://www.msaied.com/public)
- [ProjectsCase studies](https://www.msaied.com/public/projects)
- [ArticlesEngineering notes](https://www.msaied.com/public/articles)
- [CertificatesCredentials](https://www.msaied.com/public/certificates)
- [AboutHow I work](https://www.msaied.com/public#about)
- [ContactGet in touch](https://www.msaied.com/public#contact)

  [Start a conversation](https://www.msaied.com/public#contact) [WhatsApp](https://wa.me/201094619204) [Email](mailto:hello@msaied.com) 

 1. [Home](https://www.msaied.com/public)
2. /
3. [Articles](https://www.msaied.com/public/articles)
4. /
5. [Laravel](https://www.msaied.com/public/articles?category=laravel)
6. /
7. Laravel AI SDK and Laravel MCP Security Fixes: Update Now

   [Laravel](https://www.msaied.com/public/articles?category=laravel) [AI](https://www.msaied.com/public/articles?category=ai) 

 Laravel AI SDK and Laravel MCP Security Fixes: Update Now
==========================================================

 Two security advisories were published for laravel/ai and laravel/mcp on September 30, 2026. Both are fixed—run composer update today if either package is in production.

 ![](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp) [Mohamed Said](https://www.msaied.com/public#person) Published 30 Sep 2026 · Updated 30 Sep 2026 · 3 min read

ShareCopy linkCopied

 ![Laravel AI SDK and Laravel MCP Security Fixes: Update Now](https://cdn.msaied.com/722/fbe8df92faa32e9b9cee984a18bd4411.png) 

  On this page +1. [Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters](#laravel-ai-sdk-ssrf-in-the-vercel-and-ag-ui-adapters)
2. [What went wrong](#what-went-wrong)
3. [Who is affected](#who-is-affected)
4. [The fix in 1.0.1](#the-fix-in-101)
5. [Laravel MCP: OAuth Redirect Validation](#laravel-mcp-oauth-redirect-validation)
6. [What went wrong](#what-went-wrong-6)
7. [The fix](#the-fix)
8. [Affected Versions at a Glance](#affected-versions-at-a-glance)
9. [Key Takeaways](#key-takeaways)

 Two security advisories dropped on September 30, 2026 for packages that many Laravel applications now depend on: `laravel/ai` and `laravel/mcp`. Both vulnerabilities are patched, and the fix is a single Composer command away.

```bash
composer update laravel/ai laravel/mcp

```

> **Heads-up:** Neither advisory has a CVE ID assigned yet, so automated scanners that rely solely on CVE databases may not flag these issues. Manual review and updating is the only reliable path right now.

Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters
-----------------------------------------------------

The [advisory (GHSA-6qhr-3g93-pxhw)](https://github.com/laravel/ai/security/advisories/GHSA-6qhr-3g93-pxhw) affects `laravel/ai` 1.0.0 and carries a **CVSS score of 5.3 (Moderate)**.

### What went wrong

Both the Vercel AI SDK adapter and the AG-UI adapter accept file parts that include a client-supplied URL. The server fetched that URL without any validation, making it possible for an attacker who can reach a chat endpoint to force your server to issue GET requests to:

- Cloud metadata services (e.g., `169.254.169.254`)
- Localhost or loopback addresses
- Private or link-local network ranges

Because the fetched content is forwarded to the model as a file attachment, the response can surface directly in the model's reply—potentially leaking internal data.

### Who is affected

Only applications that expose the Vercel or AG-UI adapter to untrusted clients. Both adapters shipped for the first time in Laravel AI SDK 1.0, so no 0.x release is affected.

### The fix in 1.0.1

PR [\#1082](https://github.com/laravel/ai/pull/1082) introduces a URL guard that:

- Accepts only `http` and `https` schemes
- Blocks loopback, private, link-local, CGNAT, reserved, and NAT64-embedded addresses
- Validates every redirect hop and pins the connection to the resolved addresses, preventing DNS rebinding attacks

**Workaround (if you cannot upgrade immediately):** Strip or reject URL-based file parts from incoming chat requests before they reach the adapter, and restrict your server's outbound traffic to internal and metadata address ranges.

Hussam Abdulfatah reported the issue; Pushpak Chhajed wrote the fix.

Laravel MCP: OAuth Redirect Validation
--------------------------------------

The [advisory (GHSA-mx2h-h55v-pm44)](https://github.com/laravel/mcp/security/advisories/GHSA-mx2h-h55v-pm44) affects `laravel/mcp` versions below 0.9.6 and version 1.0.0. It is rated **Low**.

### What went wrong

The OAuth redirect URL was not validated strictly enough. Under certain configurations, an attacker who tricks an authenticated user into following a crafted link could redirect them to an unintended destination during the OAuth flow, potentially capturing authorization codes or tokens and taking over the user's account. Exploitation requires user interaction, and impact depends on application configuration.

### The fix

The issue is resolved in **0.9.6** and **1.0.1**. Bruno Meilick reported the vulnerability.

Affected Versions at a Glance
-----------------------------

| Package | Affected | Fixed | |---|---|---| | `laravel/ai` | 1.0.0 | 1.0.1 | | `laravel/mcp` | &lt; 0.9.6 and 1.0.0 | 0.9.6 or 1.0.1 |

Key Takeaways
-------------

- Run `composer update laravel/ai laravel/mcp` immediately if either package is in production.
- The `laravel/ai` SSRF bug (CVSS 5.3) only affects apps exposing the Vercel or AG-UI adapter to untrusted users.
- The `laravel/mcp` OAuth redirect flaw is Low severity but can lead to account takeover under certain configurations.
- No CVE IDs are assigned yet—do not rely on automated scanners alone.
- DNS rebinding protection is now built into the `laravel/ai` URL guard in 1.0.1.
- If an immediate upgrade is impossible, apply the recommended workarounds and restrict outbound network access.

---

*Source: [Laravel News — Laravel AI SDK and Laravel MCP Security Fixes: Update Now](https://laravel-news.com/laravel-ai-mcp-security-advisories)*

- [security](https://www.msaied.com/public/articles?search=security)
- [laravel-ai](https://www.msaied.com/public/articles?search=laravel-ai)
- [laravel-mcp](https://www.msaied.com/public/articles?search=laravel-mcp)
- [ssrf](https://www.msaied.com/public/articles?search=ssrf)
- [oauth](https://www.msaied.com/public/articles?search=oauth)
- [composer](https://www.msaied.com/public/articles?search=composer)

 Frequently asked questions 
---------------------------

  Which versions of laravel/ai and laravel/mcp are affected by these security advisories?laravel/ai 1.0.0 is affected by the SSRF vulnerability; it is fixed in 1.0.1. laravel/mcp versions below 0.9.6 and version 1.0.0 are affected by the OAuth redirect issue; the fix is in 0.9.6 or 1.0.1.

   My security scanner did not flag these issues. Am I safe?Not necessarily. Neither advisory has a CVE ID assigned yet, so scanners that rely solely on CVE databases may miss them. You should update both packages manually regardless of what your scanner reports.

   What should I do if I cannot upgrade laravel/ai to 1.0.1 right away?As a temporary workaround, remove or reject URL-based file parts from incoming chat requests before they reach the Vercel or AG-UI adapter, and restrict your server's outbound traffic to internal and cloud metadata address ranges.

   ![Mohamed Said](https://cdn.msaied.com/01M22N44A70A5MC2S599JP0MPH.webp)About the author
----------------

[Mohamed Said](https://www.msaied.com/public#person)Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

[About](https://www.msaied.com/public#about) [GitHub ↗](https://github.com/EG-Mohamed) [LinkedIn ↗](https://www.linkedin.com/in/msaiedm/) [WhatsApp ↗](https://wa.me/201094619204) [Email Address ↗](mailto:hello@msaied.com) [My CV ↗](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)  

   [Previous articleMigrating Pinkary from Laravel Forge to Laravel Cloud: An Engineering Playbook](https://www.msaied.com/public/articles/migrating-pinkary-from-laravel-forge-to-laravel-cloud-an-engineering-playbook) [Next articleLaravel 14 Adds a defaults() Method to Eloquent Models](https://www.msaied.com/public/articles/laravel-14-adds-a-defaults-method-to-eloquent-models)  

   On this page
-------------

1. [Laravel AI SDK: SSRF in the Vercel and AG-UI Adapters](#laravel-ai-sdk-ssrf-in-the-vercel-and-ag-ui-adapters)
2. [What went wrong](#what-went-wrong)
3. [Who is affected](#who-is-affected)
4. [The fix in 1.0.1](#the-fix-in-101)
5. [Laravel MCP: OAuth Redirect Validation](#laravel-mcp-oauth-redirect-validation)
6. [What went wrong](#what-went-wrong-6)
7. [The fix](#the-fix)
8. [Affected Versions at a Glance](#affected-versions-at-a-glance)
9. [Key Takeaways](#key-takeaways)

 ###  Have a technical challenge?

 Tell me what you’re building. I reply within two working days.

[Start a conversation](https://www.msaied.com/public#contact) 

   Related articles
-----------------

 [ ![](https://cdn.msaied.com/740/cce86edc21eddcbdd2f2454fadaf9c70.png)  · 3 min read### The Pipeline Pattern in Laravel: Custom Pipelines Beyond Middleware

5 Oct 2026 ](https://www.msaied.com/public/articles/the-pipeline-pattern-in-laravel-custom-pipelines-beyond-middleware-1) [ ![](https://cdn.msaied.com/739/2d6897fdcdcf090613f96f72a64b8a78.png)  · 4 min read### MySQL Full-Text Search in Laravel: Indexes, Relevance Scoring, and Boolean Mode

4 Oct 2026 ](https://www.msaied.com/public/articles/mysql-full-text-search-in-laravel-indexes-relevance-scoring-and-boolean-mode) [ ![](https://cdn.msaied.com/738/073696a3fefe18bec825beec5ac658f5.png)  · 4 min read### Laravel Queue Rate-Limited Middleware: Throttling Jobs Without Losing Work

4 Oct 2026 ](https://www.msaied.com/public/articles/laravel-queue-rate-limited-middleware-throttling-jobs-without-losing-work) 

  Have a technical challenge?
----------------------------

Tell me what you’re building. I reply within two working days.

 [Discuss your project ↗](https://www.msaied.com/public#contact) 

  © 2026 Mohamed Said · Built with Laravel, meant to last.Senior Backend Engineer specializing in Laravel, scalable SaaS platforms, APIs, and cloud infrastructure. I build secure, high-performance web applications that help businesses grow.

 - [Home](https://www.msaied.com/public)
- [Articles](https://www.msaied.com/public/articles)
- [Certificates](https://www.msaied.com/public/certificates)
- [GitHub](https://github.com/EG-Mohamed)
- [LinkedIn](https://www.linkedin.com/in/msaiedm/)
- [WhatsApp](https://wa.me/201094619204)
- [Email Address](mailto:hello@msaied.com)
- [My CV](https://drive.google.com/file/u/0/d/1MF20IPRJyzfy32mhEutjL5EpSls0w2Q8/view)
- [Sitemap](https://www.msaied.com/public/sitemap.xml)
