1
votes
Laravel AI SDK and Laravel MCP Security Fixes: Update Now
The first advisory covers a server-side request forgery (SSRF) bug in laravel/ai 1.0.0. It's rated Moderate, with a CVSS score of 5.3.
The Vercel AI SDK adapter and the AG-UI adapter accept file parts with a URL from the client, and the server fetched that URL without validating it.
The Vercel AI SDK adapter and the AG-UI adapter accept file parts with a URL from the client, and the server fetched that URL without validating it.