Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
- Severity:
- Low
Description
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
Recommendation
Update the ai package to the latest compatible version. Followings are version details:
Affected version(s): **>= 5.1.0-beta.0, < 5.1.0-beta.9 < 5.0.52** Patched version(s): **5.1.0-beta.9 5.0.52**
References
Related Issues
- matrix-js-sdk has insufficient validation when considering a room to be upgraded by another - CVE-2025-59160
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514
- OpenPGP.js's message signature verification can be spoofed - CVE-2025-47934
- Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nuxt - CVE-2025-65944
You might also like:
- Tags:
- npm
- ai
Anything's wrong? Let us know Last updated on December 02, 2025


