Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
Low severity
GitHub Reviewed
Published
Nov 7, 2025
to the GitHub Advisory Database
•
Updated Nov 7, 2025
Package
Affected versions
< 5.0.52
>= 5.1.0-beta.0, < 5.1.0-beta.9
Patched versions
5.0.52
5.1.0-beta.9
Description
Published by the National Vulnerability Database
Nov 7, 2025
Published to the GitHub Advisory Database
Nov 7, 2025
Reviewed
Nov 7, 2025
Last updated
Nov 7, 2025
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
References