{"data":{"id":"16019759-8db1-4df4-92b1-24735e6ecd11","title":"GHSA-rwvc-j5jr-mgvh: Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files","summary":"A vulnerability in Vercel's AI SDK allowed users to bypass filetype whitelists when uploading files. The flaw is tracked as GHSA-rwvc-j5jr-mgvh and is fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta.","solution":"Fixed in 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. All users are encouraged to upgrade.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-rwvc-j5jr-mgvh","publishedAt":"2025-11-07T03:30:25.000Z","cveId":"CVE-2025-48985","cweIds":["CWE-20","CWE-682"],"cvssScore":"3.7","cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["ai@< 5.0.52 (fixed: 5.0.52)","ai@>= 5.1.0-beta.0, < 5.1.0-beta.9 (fixed: 5.1.0-beta.9)"],"affectedPackageNames":["ai"],"affectedPackageRefs":["npm:ai"],"affectedVendors":[],"affectedVendorsRaw":["Vercel AI SDK"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"network","attackComplexity":"high","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00284,"epssCheckedAt":"2026-10-10T04:57:13.049Z","kevDateAdded":null,"advisoryAliases":["GHSA-rwvc-j5jr-mgvh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-11-07T03:30:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}