Vulnerabilities/

Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files

Severity:
Low

Description

A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.

Recommendation

Update the ai package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ai
Anything's wrong? Let us know Last updated on December 02, 2025