A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rwvc-j5jr-mgvh Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Vercel
Vercel ai Sdk
Vercel vercel
Vendors & Products Vercel
Vercel ai Sdk
Vercel vercel

Fri, 07 Nov 2025 01:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-11-07T18:35:24.238Z

Reserved: 2025-05-29T15:00:04.775Z

Link: CVE-2025-48985

cve-icon Vulnrichment

Updated: 2025-11-07T18:35:18.998Z

cve-icon NVD

Status : Received

Published: 2025-11-07T01:15:36.567

Modified: 2025-11-07T01:15:36.567

Link: CVE-2025-48985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-07T10:53:37Z