LOW3.7
GHSA-rwvc-j5jr-mgvh
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Quick fix
GHSA-rwvc-j5jr-mgvh — ai: upgrade to the fixed version with the command below.
npm install ai@5.0.52Details
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-48985[ADVISORY]
- https://github.com/vercel/ai/issues/8881[WEB]
- https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed[WEB]
- https://github.com/vercel/ai[PACKAGE]
- https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk[WEB]