CVE-2025-48985: Input Validation
A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48985?
CVE-2025-48985 is classified as a medium severity vulnerability due to its potential to allow filetype whitelists to be bypassed.
How do I fix CVE-2025-48985?
To fix CVE-2025-48985, upgrade to versions 5.0.52, 5.1.0-beta.9, or 6.0.0-beta of the Vercel AI SDK.
What impact does CVE-2025-48985 have?
CVE-2025-48985 could result in unauthorized file uploads that circumvent established filetype restrictions.
Who is affected by CVE-2025-48985?
All users of the Vercel AI SDK prior to versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta are affected by CVE-2025-48985.
Is CVE-2025-48985 already patched?
Yes, CVE-2025-48985 has been patched in the specified versions of the Vercel AI SDK.