What changed
Laravel AI SDK 1.0.0 accepted remote file parts through its Vercel AI SDK and AG-UI adapters and fetched those URLs server-side without validating the destination. An untrusted caller could therefore make the application issue GET requests to localhost, private networks or cloud metadata endpoints, with the fetched response passed onward as a model attachment. Laravel AI SDK 1.0.1 adds a URL guard that restricts schemes to HTTP/HTTPS, blocks loopback, private, link-local, CGNAT, reserved and NAT64-embedded addresses, checks every redirect hop and pins connections to validated addresses to resist DNS rebinding.
Why it matters
AI adapters increasingly translate rich client input into server-side tool or model operations. A file URL can look like ordinary multimodal input while silently creating an SSRF primitive with access to network locations the browser cannot reach. Laravel's patch makes that boundary explicit and gives builders a concrete checklist for any framework feature that dereferences user-controlled URLs.
The vulnerable boundary is remote file ingestion
The affected adapters accept file parts containing URLs. In 1.0.0 the server fetched those URLs without first proving that the destination was safe. The issue matters only where an application exposes one of those adapter-backed chat endpoints to untrusted callers, but in that configuration the server's own network position becomes part of the attack surface.
The fix handles more than obvious private IPs
Version 1.0.1 does not merely reject localhost strings. The guard restricts schemes, rejects private and reserved address classes, validates redirect destinations and pins the connection to addresses already checked. Those last two controls matter because redirect chains and DNS rebinding can otherwise turn an apparently public URL into a request to an internal target after initial validation.
CVE-only scanning may not catch the update
The advisory is rated Moderate at CVSS 5.3 but currently has no CVE identifier. Teams that discover dependency risk only through CVE-based feeds may therefore miss the reason to update even though a patched package is available.