Junglewise Threat Intelligence

CVE-2026-8768: Vercel AI SSRF via HTTP redirect in provider-utils

CVE-2026-8768 · Severity: high · CVSS 7.3 · Published 2026-05-17

Technologies: Vercel AI SDK. Vendors: Vercel.

Executive brief

A vulnerability exists in the Vercel AI SDK, a toolkit used by developers to build AI-powered applications. The software fails to properly restrict network requests when downloading external content like images, allowing an attacker to force the server to connect to internal systems that should be private. This could allow an attacker to interact with internal databases, cloud metadata services, or other protected infrastructure, potentially leading to unauthorized actions or service disruptions.

Technical details

A Blind Server-Side Request Forgery (SSRF) vulnerability exists in the `validateDownloadUrl` function within `packages/provider-utils/src/download-blob.ts`. The root cause is a Time-of-Check to Time-of-Use (TOCTOU) flaw where the SDK validates an initial URL but uses the native `fetch()` API with the default `redirect: 'follow'` behavior. An attacker can provide a benign-looking URL that passes initial validation but redirects to a restricted internal IP (e.g., 127.0.0.1 or 169.254.169.254). Although the SDK performs a post-flight check on the redirected URL and prevents the attacker from reading the response, the HTTP GET request is successfully executed against the internal target before the check occurs. This allows unauthenticated remote attackers to trigger internal REST actions or perform port scanning.

Affected products

  • Vercel ai-sdk/provider-utils up to 3.0.97
  • Vercel ai up to 3.0.97

Timeline

  • 2026-04-04: disclosed: Vulnerability details shared via GitHub Gist by researcher YLChen-007
  • 2026-05-17: advisory: CVE-2026-8768 published

References

Related threats