← Back

CVE-2025-48985

nvd nist
Published: Nov 7, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade. More details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk

Affected (10)

Products: Vercel: Ai
1 product
Ai
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Vercel
Before 5.0.52
Version 5.1.0 beta0
Version 5.1.0 beta1
Version 5.1.0 beta2
Version 5.1.0 beta3
Version 5.1.0 beta4
Version 5.1.0 beta5
Version 5.1.0 beta6
Version 5.1.0 beta7
Version 5.1.0 beta8

Timeline

No history available yet.