Laravel AI SDK and MCP get security fixes for SSRF and OAuth redirects
Laravel patched laravel/ai 1.0.0 (SSRF via unvalidated file URLs in the Vercel/AG-UI adapters; CVSS 5.3) and laravel/mcp (low-severity OAuth redirect validation). Upgrade to laravel/ai 1.0.1 and laravel/mcp 0.9.6 or 1.0.1—neither advisory has a CVE yet.