{"id":"CVE-2025-48985","aliases":["GHSA-rwvc-j5jr-mgvh"],"url":"https://o3.security/vulnerability/CVE-2025-48985","summary":"Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files","details":"A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.\r\n\r\nMore details: https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk","published":"2025-11-07T00:43:28.027Z","modified":"2026-08-12T03:51:48.425744567Z","cvss":{"score":3.7,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ai","fixedVersion":"5.0.52"},{"ecosystem":"npm","name":"ai","fixedVersion":"5.1.0-beta.9"}],"fix":{"url":"https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed","label":"vercel/ai@930399b"},"references":[{"type":"WEB","url":"https://vercel.com/changelog/cve-2025-48985-input-validation-bypass-on-ai-sdk"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48985.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48985"},{"type":"FIX","url":"https://github.com/vercel/ai/commit/930399bb9839a8baf3d349614106d78268775eed"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.425744567Z"}}