LOW 3.7 npm
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
GHSA-rwvc-j5jr-mgvh · CVE-2025-48985
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-48985
- WEB https://github.com/vercel/ai/issues/8881
- WEB https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed
- PACKAGE https://github.com/vercel/ai
- WEB https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Ready to move
Start Securing
Free, no credit card | First findings in minutes