More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rwvc-j5jr-mgvh | Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files |
Wed, 04 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vercel ai
|
|
| CPEs | cpe:2.3:a:vercel:ai:*:*:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta0:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta1:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta2:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta3:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta4:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta5:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta6:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta7:*:*:*:*:*:* cpe:2.3:a:vercel:ai:5.1.0:beta8:*:*:*:*:*:* |
|
| Vendors & Products |
Vercel ai
|
Mon, 01 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 07 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vercel
Vercel ai Sdk Vercel vercel |
|
| Vendors & Products |
Vercel
Vercel ai Sdk Vercel vercel |
Fri, 07 Nov 2025 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-12-01T20:12:57.508Z
Reserved: 2025-05-29T15:00:04.775Z
Link: CVE-2025-48985
Updated: 2025-11-07T18:35:18.998Z
Status : Analyzed
Published: 2025-11-07T01:15:36.567
Modified: 2026-02-04T21:11:11.667
Link: CVE-2025-48985
No data.
OpenCVE Enrichment
Updated: 2025-11-07T10:53:37Z
Github GHSA