LowVulnerability
GHSA-rwvc-j5jr-mgvh: Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
- Identifiers
- CVE-2025-48985GHSA-rwvc-j5jr-mgvh
- Published
- Record updated
- Affected
- ai < 5.0.52, fixed in 5.0.52
- ai >= 5.1.0-beta.0, < 5.1.0-beta.9, fixed in 5.1.0-beta.9
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
A vulnerability in Vercel's AI SDK allowed users to bypass filetype whitelists when uploading files. The flaw is tracked as GHSA-rwvc-j5jr-mgvh and is fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta.
Mitigation
Fixed in 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. All users are encouraged to upgrade.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- ainpmLLM dependency since 2014-02-21 · 6 tracked dependents
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading