A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have allowed users to bypass filetype whitelists when uploading files. All users are encouraged to upgrade.
{
"github_reviewed": true,
"severity": "LOW",
"cwe_ids": [
"CWE-682"
],
"nvd_published_at": "2025-11-07T01:15:36Z",
"github_reviewed_at": "2025-11-07T17:39:01Z"
}