Executive brief
Vercel's AI SDK contains a vulnerability in its file upload validation logic that allows users to bypass intended filetype restrictions. This could enable developers using the SDK to accept file types they intended to block, potentially leading to upload of malicious or unexpected file types in applications built with this SDK.
Technical details
The vulnerability is an input validation bypass (CWE-20, CWE-682) in Vercel's AI SDK's file upload handling mechanism. The root cause lies in the download logic that filters out images with missing data, which inadvertently changes the index mapping between input and output images, allowing validation checks to be circumvented. The attack is network-accessible and requires no authentication or user interaction. An attacker can upload files that should have been blocked by the SDK's filetype whitelist. The issue has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta.
Affected products
- Vercel AI SDK before 5.0.52, 5.1.0-beta.0 to before 5.1.0-beta.9, before 6.0.0-beta
Timeline
- 2025-11-07: disclosed: Vulnerability published as CVE-2025-48985 and GHSA-rwvc-j5jr-mgvh
- 2025-11-07: patched: Fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta