5.3

CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VercelAi Version < 5.0.52
VercelAi Version5.1.0 Updatebeta0
VercelAi Version5.1.0 Updatebeta1
VercelAi Version5.1.0 Updatebeta2
VercelAi Version5.1.0 Updatebeta3
VercelAi Version5.1.0 Updatebeta4
VercelAi Version5.1.0 Updatebeta5
VercelAi Version5.1.0 Updatebeta6
VercelAi Version5.1.0 Updatebeta7
VercelAi Version5.1.0 Updatebeta8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.373
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
support@hackerone.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.