5.3

CVE-2025-48985

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vercel ≫ Ai Version < 5.0.52
Vercel ≫ Ai Version 5.1.0 Update beta0
Vercel ≫ Ai Version 5.1.0 Update beta1
Vercel ≫ Ai Version 5.1.0 Update beta2
Vercel ≫ Ai Version 5.1.0 Update beta3
Vercel ≫ Ai Version 5.1.0 Update beta4
Vercel ≫ Ai Version 5.1.0 Update beta5
Vercel ≫ Ai Version 5.1.0 Update beta6
Vercel ≫ Ai Version 5.1.0 Update beta7
Vercel ≫ Ai Version 5.1.0 Update beta8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
HackerOne 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed
Patch
https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Vendor Advisory