Description
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
Recommendation
Update the ai package to the latest compatible version. Followings are version details:
Affected version(s): **>= 5.1.0-beta.0, < 5.1.0-beta.9 < 5.0.52** Patched version(s): **5.1.0-beta.9 5.0.52**
References
Could your website be exposed too?
SmartScanner can check your website for Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files and gives you actionable findings to investigate.
Start a free scanRelated Issues
- matrix-js-sdk has insufficient validation when considering a room to be upgraded by another - CVE-2025-59160
- Fiora chat user avatar is vulnerable to XSS via SVG files - CVE-2025-56514
- OpenPGP.js's message signature verification can be spoofed - CVE-2025-47934
- Sentry's sensitive headers are leaked when `sendDefaultPii` is set to `true` - @sentry/nuxt - CVE-2025-65944


