When // inject single quote in array $partIds = ["1'", "2'"]; $model->cars()->attach($partIds); Query will crash, so vulnerabilities will able to attack by sql injection