laravel/ai is vulnerable to Server-Side Request Forgery (SSRF)
53
Medium Risk
The Vercel AI SDK adapter and the AG-UI adapter accept a client supplied file URL and fetch it from the server without validating the target host. A chat request with a URL that points at an internal address, such as a cloud metadata endpoint, localhost, or a private network, makes the server send that request and return the response body to the model as a file attachment, leaking internal service responses into the model's reply through server-side request forgery. The fix restricts remote file URLs to http/https, blocks loopback, private, link-local, and reserved addresses, and pins the connection across redirects to stop DNS rebinding.
You are affected if you are using a version that falls within the vulnerable range and you expose the Vercel AI SDK adapter or the AG-UI adapter to untrusted clients.
laravel/ai is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.0.0 - 1.0.0.
Upgrade the laravel/ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.