Back to Blog
Laravel AI SDK and MCP Security Fixes: Patch 1.0.1 Before You Ship Chat
Laravel published security advisories for laravel/ai (SSRF in chat adapters) and laravel/mcp (OAuth redirect). If either package runs in production, land 1.0.1 today.
Back
Engineering
Table of contents
Two security advisories landed for Laravel's first-party AI and MCP packages around late September 2026. One is a server-side request forgery in chat adapters. The other is an OAuth redirect weakness. If you installed either package at 1.0.0 and polished your chat UX before patching, you shipped the bug.
Laravel AI SDK 1.0.1 and MCP 0.9.6 / 1.0.1 fix both. If you run production chat that fetches client URLs or production OAuth that hands out authorization codes, patch before you do anything else.
Quick Answer
Update both packages.
bash
composer update laravel/ai laravel/mcpBump laravel/ai to 1.0.1. Bump laravel/mcp to 0.9.6 or 1.0.1.
Scanners that only watch CVE feeds may miss these advisories. Neither has a CVE ID yet. The GitHub Security Advisory identifiers are GHSA-6qhr-3g93-pxhw (laravel/ai) and GHSA-mx2h-h55v-pm44 (laravel/mcp).
laravel/ai: SSRF in Vercel and AG-UI adapters (GHSA-6qhr-3g93-pxhw)
The bigger advisory is GHSA-6qhr-3g93-pxhw. It covers Laravel\Ai\Vercel\Vercel and Laravel\Ai\AgentUserInteraction\AgentUserInteraction. Both adapters accept a file part with a URL from the client and fetch that URL on the server. Neither validated the URL before making the request.
A caller of a chat endpoint on either adapter could pass an internal URL: cloud metadata (169.254.169.254), localhost, private networks (10.0.0.0/8, 192.168.0.0/16, 172.16.0.0/12). The server would GET that address. The response body goes to the model as a file attachment, and the model can echo it in the reply.
The CVSS 3.1 score is 5.3, severity moderate (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). You leak internal data. You do not execute arbitrary code.
The advisory scope notes that only apps exposing one of these adapters to untrusted clients are affected. Both adapters first shipped in 1.0.0. If you run 0.x, you do not have them.
The fix in PR #1082 runs remote file URLs through a guard. The guard accepts only http and https schemes. It blocks loopback, private, link-local, CGNAT, reserved, and NAT64-embedded addresses. It checks every redirect hop and pins the connection to checked addresses (DNS rebinding mitigation).
If you cannot upgrade, remove or reject URL-based file parts before they reach the adapter, or block outbound traffic to internal addresses at the network layer.
Hussam Abdulfatah (Hussam3bd) reported the bug. pushpak1300 shipped the fix.
The same class of bug appeared in Vercel AI SDK (CVE-2026-8768 / GHSA-8rqj-9gxc-63cr). The Laravel advisory fixes a similar pattern in the Laravel adapters, not the Vercel bug itself.
laravel/mcp: OAuth redirect (GHSA-mx2h-h55v-pm44)
The second advisory is GHSA-mx2h-h55v-pm44, published Sep 24, 2026. It covers an OAuth redirect URL validation weakness in laravel/mcp before 0.9.6 and before 1.0.1.
A weakness in OAuth redirect URL validation could send an authenticated user to an unintended destination during OAuth. Under certain configs, a crafted link plus user interaction could obtain OAuth data (authorization codes or tokens) and compromise the account.
The advisory notes that whether you are affected depends on configuration. The bug requires user interaction. The severity is low. The weakness is CWE-601 (open redirect).
No CVE has been assigned. The advisory patched versions are 0.9.6 and 1.0.1.
Practical check: when should you treat this as urgent?
If you expose Vercel Chat or AG-UI streaming to the public internet on laravel/ai 1.0.0, treat the SSRF fix as production urgent. Internal addresses on AWS, GCP, Azure, and private networks all leak if a client sends a crafted file URL.
If you only use the AI SDK without the Vercel or AG-UI adapters (for example, you call models directly or use a different chat format), the advisory scope says you are not affected. Read the advisory to confirm which classes you import.
If you run MCP OAuth, patch to 0.9.6 or 1.0.1. The redirect bug is low severity and config-dependent, but there is no reason to stay on a version the advisory calls out.
My take
AI chat adapters that fetch client-supplied URLs are a classic SSRF trap. AWS metadata, Kubernetes service tokens, localhost databases, and internal admin panels are all one file: { url: "http://169.254.169.254/latest/meta-data/iam/security-credentials/" } away when the adapter does not validate.
First-party packages shipping 1.0.1 patches in the first week after 1.0.0 is normal. The AI SDK landed features fast. Vercel shipped a similar fix around the same time. Laravel caught up. Still update.
Patch today: laravel/ai to 1.0.1, laravel/mcp to 0.9.6 or 1.0.1. The SSRF fix closes a real leak. The OAuth redirect fix is lower severity but still worth landing. If you run production chat or OAuth on these packages, you want both fixes.
Sources
- GitHub Security Advisory GHSA-6qhr-3g93-pxhw (laravel/ai SSRF)
- GitHub Security Advisory GHSA-mx2h-h55v-pm44 (laravel/mcp OAuth redirect)
- Laravel News: Laravel AI and MCP Security Advisories
- laravel/ai PR #1082 (SSRF fix implementation)
Comments
No comments yet
Loading comments...