Skip to content
LowVulnerability

GHSA-rwvc-j5jr-mgvh: Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

Published
Record updated
View JSON
Affected
  • ai < 5.0.52, fixed in 5.0.52
  • ai >= 5.1.0-beta.0, < 5.1.0-beta.9, fixed in 5.1.0-beta.9
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

A vulnerability in Vercel's AI SDK allowed users to bypass filetype whitelists when uploading files. The flaw is tracked as GHSA-rwvc-j5jr-mgvh and is fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta.

Mitigation

Fixed in 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. All users are encouraged to upgrade.