vibehacker
News
Laravel News ·

Laravel AI SDK and MCP get security fixes for SSRF and OAuth redirects

Laravel patched laravel/ai 1.0.0 (SSRF via unvalidated file URLs in the Vercel/AG-UI adapters; CVSS 5.3) and laravel/mcp (low-severity OAuth redirect validation). Upgrade to laravel/ai 1.0.1 and laravel/mcp 0.9.6 or 1.0.1—neither advisory has a CVE yet.

More news

View all

Factory CEO accuses board adviser of spying for rival Cognition

Factory CEO Matan Grinberg says he fired board adviser Chris Degnan after learning Degnan held recurring talks with Cognition while advising Factory; Degnan says he resigned and joined Cognition as CRO, denying any confidential sharing. Cognition CEO Scott Wu also denied the claims…

TechCrunch

Five MCP auth mechanisms ship in two weeks after security disclosures

Between mid September and Sept 30, Okta Agent SSO, SSOJet, Rubrik MCP, GitHub Copilot’s MCP auth customizer, and Operant’s Okta linked gateway each shipped MCP authentication—none interoperable—after LiteLLM’s CISA KEV bypass and Cycode’s MCP Python SDK OAuth theft. Identity is catching up; NSA noted RBAC at connect time is still open…

Forkast

Discobox: open-source VMs give coding agents their own machines

Obot open sourced Discobox (Sept 30): each coding agent gets an isolated Mac VM with its own desktop and browser—Claude Code, Codex, and OpenCode work today. Agents never see real secrets; they get sentinels, and an AI judge plus egress proxy swaps tokens only for approved hosts and purposes…

Obot

Spotted something we missed? Start a thread.